What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form Pro: from n/a through 2.6.4.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
What the vulnerability does
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bit Apps Bit Form Pro allows File Manipulation.This issue affects Bit Form Pro: from n/a through 2.6.4.
Explanation of Vulnerability in Simple Terms
Bit Form Pro versions up to 2.6.4 contain a path traversal vulnerability that allows an unauthenticated attacker to cause a denial of service by making the site unresponsive or unavailable. The vulnerability exists in how the plugin handles file paths without proper validation. No authentication or user interaction is required to exploit this issue.
What an attacker can do
Make the site unavailable or unresponsive by exploiting path traversal to trigger resource exhaustion.
Potential impact on your site
Your site may become unavailable or slow to respond without warning or user action.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities