Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all executable content (e.g., .phtml or .php.bak) is blocked.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://JQueryForm.com | vendor advisory |
https://www.nou-systems.com/cyber-security | third party advisory |
https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560 | third party advisory |