Ninja Forms Contact Form 2.9.36 - 2.9.42 - Unauthenticated Arbitrary File Upload
2016-05-05 00:00
James GolovichStrategic Overview
StatusPatched in 2.9.42.1
Affected PluginNinja Forms – The Contact Form Builder That Grows With You
Affected Version
2.9.36 – 2.9.42CVSS9.8Critical
CVE
CVE-2016-1209Vulnerability Overview
Versions 2.9.36 to 2.9.42 of the Ninja Forms plugin contain an unauthenticated file upload vulnerability, allowing guests to upload arbitrary PHP code that can be executed in the context of the web server.
Technical Analysis
REMEDIATION: Update to version 2.9.42.1, or a newer patched version --- IDENTIFIER: CWE-434 (Unrestricted Upload of File with Dangerous Type) The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C