ZeroHour

CVE-2021-20104

CVSS 3.1
8.1 high
EPSS
2%p81
Published
()
Modified
Description

Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.

Vendors
machform
Products
machform
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.