CVE-2024-28890
MEDIUMIncsub Forminator < 1.29.0 - Unrestricted File Upload
Title source: ruleDescription
Forminator prior to 1.29.0 contains an unrestricted upload of file with dangerous type vulnerability. If this vulnerability is exploited, a remote attacker may obtain sensitive information by accessing files on the server, alter the site that uses the plugin, and cause a denial-of-service (DoS) condition.
References (3)
Core 3
Scores
CVSS v3
5.3
EPSS
0.0085
EPSS Percentile
75.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-434
Status
published
Products (1)
incsub/forminator
< 1.29.0
Published
Apr 23, 2024
Tracked Since
Feb 18, 2026