Path Traversal Vulnerability Affects BuddyForms from n/a to 2.8.8
CVE-2024-32830
8.6HIGH
Key Information
- Vendor
- Themekraft
- Status
- Buddyforms
- Vendor
- CVE Published:
- 17 May 2024
Summary
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThemeKraft BuddyForms allows Server Side Request Forgery, Relative Path Traversal.This issue affects BuddyForms: from n/a through 2.8.8.
Affected Version(s)
BuddyForms <= 2.8.8
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
Yudistira Arya (Patchstack Alliance)