CVE-2020-9364
Creative Contact Form 4.6.2 Directory Traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
An issue was discovered in helpers/mailer.php in the Creative Contact Form extension 4.6.2 before 2019-12-03 for Joomla!. A directory traversal vulnerability resides in the filename field for uploaded attachments via the creativecontactform_upload parameter. An attacker could exploit this vulnerability with the "Send me a copy" option to receive any files of the filesystem via email.
Se detectó un problema en el archivo helpers/mailer.php en la extension Creative Contact Form versiones anteriores a 4.6.2 hasta el 2019-12-03 para Joomla!. Una vulnerabilidad de salto de directorio reside en el campo filename para los archivos adjuntos cargados por medio del parámetro creativecontactform_upload. Un atacante podría explotar esta vulnerabilidad con la opción "Send me a copy" para recibir cualquiera de los archivos del sistema de archivos por medio del correo electrónico.
Creative Contact Form version 4.6.2 before Dec 03 2019 suffers from a directory traversal vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-24 CVE Reserved
- 2020-03-04 CVE Published
- 2023-11-20 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://extensions.joomla.org/extension/creative-contact-form | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Creative-solutions Search vendor "Creative-solutions" | Creative Contact Form Search vendor "Creative-solutions" for product "Creative Contact Form" | 4.6.2 Search vendor "Creative-solutions" for product "Creative Contact Form" and version "4.6.2" | joomla\! |
Affected
|