CVE-2016-9493 - CVE House
Back to Database
Status published Medium CVE-2016-9493

PHP forms generated using the PHP FormMail Generator are vulnerable to stored cross-site scripting

Vulnerability Description

The code generated by PHP FormMail Generator prior to 17 December 2016 is vulnerable to stored cross-site scripting. In the generated form.lib.php file, upload file types are checked against a hard-coded list of dangerous extensions. This list does not include all variations of PHP files, which may lead to execution of the contained PHP code if the attacker can guess the uploaded filename. The form by default appends a short random string to the end of the filename.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-9493

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Thanks to Ibram Marzouk for reporting this vulnerability.

Affected Vendor

PHP FormMail

View all reports →

Affected Software

Generator
Vulnerable Versions:
17/12/2016

Timeline

Official Publish: July 13th, 2018
Last Modified: August 6th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)