Main
Vulnerability Database
Exploits
ID:9827 - Exploit for Arbitrary file upload in Forminator Contact Form, Poll & Quiz Builder - CVE-2023-4596
ID:9827 - Exploit for Arbitrary file upload in Forminator Contact Form, Poll & Quiz Builder - CVE-2023-4596
Published: May 23, 2024
Vulnerability identifier: #VU80191
Vulnerability risk: High
CVE-ID: CVE-2023-4596
CWE-ID: CWE-434
Exploitation vector: Remote access
Vulnerable software:
Forminator Contact Form, Poll & Quiz Builder
Forminator Contact Form, Poll & Quiz Builder
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of file extension when uploading files within the upload_post_image() function. A remote non-authenticated attacker can upload and execute arbitrary file on the system.
Remediation
Install update from vendor's website.