Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2014-6446

HIGH · 7.5 CVSS Gepubliceerd: CWE-94

Beschrijving

The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers to upload arbitrary files and execute arbitrary PHP code via a request to utilities/code_generator.php.

Vendors

Infusionsoft Gravity Forms Project

Affected products

Infusionsoft Gravity Forms

References