Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.
References
Configurations
History
02 Jul 2021, 19:51
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:machform:machform:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 6.8
v3 : 8.1 |
References | (MISC) https://www.tenable.com/security/research/tra-2021-25,https://www.machform.com/blog-machform-16-released/ - Exploit, Third Party Advisory | |
CWE | CWE-434 |
29 Jun 2021, 16:42
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-29 16:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-20104
Mitre link : CVE-2021-20104
CVE.ORG link : CVE-2021-20104
JSON object : View
Products Affected
machform
- machform
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type