A Public Form Became an Unauthenticated Web Shell.

Elementor Pro 4.2.1 and earlier can let an unauthenticated attacker bypass form-upload validation and place executable PHP in a public directory.

Elementor Pro 4.2.1 and earlier can let an unauthenticated attacker bypass form-upload validation and place executable PHP in a public directory.

Adobe fixed 13 ColdFusion vulnerabilities, including six CVSS 10 code-execution flaws. One path-traversal issue was already under attack.