CVE-2024-9507
概要

The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 2.15.2 due to improper input validation within the iconUpload function. This makes it possible for authenticated attackers, with Administrator-level access and above, to leverage a PHP filter chain attack and read the contents of arbitrary files on the server, which can contain sensitive information.

公表日 2024年10月11日22:15
登録日 2024年10月12日5:00
最終更新日 2024年10月15日21:58
関連情報、対策とツール
共通脆弱性一覧