Vulnerabilities > CVE-2016-9483 - Deserialization of Untrusted Data vulnerability in Jqueryform PHP Formmail Generator

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
jqueryform
CWE-502
critical

Summary

The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with CVE-2016-9484 to perform local file inclusion attacks and obtain files from the server.

Vulnerable Configurations

Part Description Count
Application
Jqueryform
1

Common Weakness Enumeration (CWE)