Machform prior to version 16 is vulnerable to unauthenticated remote code execution due to insufficient sanitization of file attachments uploaded with forms through upload.php.
References
Configurations
History
No history.
Information
Published : 2021-06-29 16:15
Updated : 2023-11-07 03:28
NVD link : CVE-2021-20104
Mitre link : CVE-2021-20104
CVE.ORG link : CVE-2021-20104
JSON object : View
Products Affected
machform
- machform
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type