Back to search
CVE-2022-24984
Published: Feb 16, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
Forms generated by JQueryForm.com before 2022-02-05 (if file-upload capability is enabled) allow remote unauthenticated attackers to upload executable files and achieve remote code execution. This occurs because file-extension checks occur on the client side, and because not all executable content (e.g., .phtml or .php.bak) is blocked.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://JQueryForm.com
x_refsource_MISC
https://www.nou-systems.com/cyber-security
x_refsource_MISC
https://gist.github.com/pb-nsi/4d0a1ede76d4e97083b3435f820bf560
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now