Lucene search

K
nvd[email protected]NVD:CVE-2023-4666
HistoryOct 16, 2023 - 8:15 p.m.

CVE-2023-4666

2023-10-1620:15:15
web.nvd.nist.gov
2
form maker
10web
wordpress
signature validation
rce

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

54.0%

The Form Maker by 10Web WordPress plugin before 1.15.20 does not validate signatures when creating them on the server from user input, allowing unauthenticated users to create arbitrary files and lead to RCE

Affected configurations

Nvd
Node
10webform_makerRange<1.15.20wordpress
VendorProductVersionCPE
10webform_maker*cpe:2.3:a:10web:form_maker:*:*:*:*:*:wordpress:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.002

Percentile

54.0%

Related for NVD:CVE-2023-4666