peter bassill · operator
$ cve CVE-2016-9483 JSON

CVE-2016-9483

9.8
CRITICAL · CVSS 3.0 · EPSS 3.4% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

The PHP form code generated by PHP FormMail Generator deserializes untrusted input as part of the phpfmg_filman_download() function. A remote unauthenticated attacker may be able to use this vulnerability to inject PHP code, or along with CVE-2016-9484 to perform local file inclusion attacks and obtain files from the server.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.43% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2018-07-13
Last modified2026-06-17

Affected (1)

VendorProduct
jqueryformphp formmail generator

References

→ the Explorer  ·  watch your stack  ·  NVD