CVE-2020-35489
Contact Form 7 <= 5.3.1 - Arbitrary File Upload via Bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The contact-form-7 (aka Contact Form 7) plugin before 5.3.2 for WordPress allows Unrestricted File Upload and remote code execution because a filename may contain special characters.
El plugin contact-form-7 (también se conoce como Contact Form 7) versiones anteriores a 5.3.2 para WordPress, permite una Carga de Archivos Sin Restricciones y una ejecución de código remota porque un nombre de archivo puede contener caracteres especiales
The Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads in versions up to 5.3.2. This is due to the fact that the plugin allows filenames to contain special characters which may make extension filter evasion possible on certain configurations. Our team was not able to reproduce this issue which leads us to believe there is a high attack complexity or special configuration requirement.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-17 CVE Reserved
- 2020-12-17 CVE Published
- 2020-12-25 First Exploit
- 2024-08-04 CVE Updated
- 2024-10-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/contact-form-7/#developers | Release Notes | |
https://wpscan.com/vulnerability/10508 | Third Party Advisory | |
https://www.getastra.com/blog/911/plugin-exploit/contact-form-7-unrestricted-file-upload | Third Party Advisory | |
https://www.jinsonvarghese.com/unrestricted-file-upload-in-contact-form-7 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/dn9uy3n/Check-WP-CVE-2020-35489 | 2020-12-25 | |
https://github.com/Cappricio-Securities/CVE-2020-35489 | 2024-06-21 | |
https://github.com/X0UCYB3R/Check-WP-CVE-2020-35489 | 2020-12-25 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://contactform7.com/2020/12/17/contact-form-7-532 | 2020-12-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rocklobster Search vendor "Rocklobster" | Contact Form 7 Search vendor "Rocklobster" for product "Contact Form 7" | < 5.3.2 Search vendor "Rocklobster" for product "Contact Form 7" and version " < 5.3.2" | wordpress |
Affected
|