ZeroHour

CVE-2018-6409

PoC ×2
CVSS 3.0
5.3 medium
EPSS
15%p96
Published
()
Modified
Description

An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.

Vendors
machform
Products
machform
Weakness
CWE-22
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.