An open redirect in the Ninja Forms plugin before 3.3.19.1 for WordPress allows Remote Attackers to redirect a user via the lib/StepProcessing/step-processing.php (aka submissions download page) redirect parameter.
References
Link | Resource |
---|---|
https://wordpress.org/plugins/ninja-forms/#developers | Product Third Party Advisory |
https://plugins.trac.wordpress.org/changeset/1982808/ninja-forms/trunk/lib/StepProcessing/step-processing.php | Exploit Third Party Advisory |
https://wpvulndb.com/vulnerabilities/9154 |
Configurations
Information
Published : 2018-12-02 22:29
Updated : 2020-03-03 09:15
NVD link : CVE-2018-19796
Mitre link : CVE-2018-19796
JSON object : View
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Products Affected
ninjaforms
- ninja_forms