What the vulnerability does
01Description
Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
What the vulnerability does
Unrestricted Upload of File with Dangerous Type vulnerability in Piotnet Piotnet Forms.This issue affects Piotnet Forms: from n/a through 1.0.25.
Explanation of Vulnerability in Simple Terms
Piotnet Forms versions up to 1.0.25 do not properly validate file uploads, allowing an attacker to upload malicious files to the server. An attacker can exploit this over the network without authentication to upload and execute arbitrary code, potentially compromising the entire site. The vulnerability affects confidentiality, integrity, and availability.
What an attacker can do
Upload and execute malicious files on the server without authentication.
Potential impact on your site
An attacker can run arbitrary code on your site, steal data, modify content, or take the site offline.
Conditions required to exploit
Network access to the vulnerable form; no authentication required.
Key dates
External resources
Related vulnerabilities