Made I.T. Forms (through 2.8.0) contains an unrestricted upload of file with dangerous type vulnerability that allows an attacker to upload a server-executable file (e.g., a web shell) to the web server. The core issue is insufficient server-side validation and/or unsafe handling of uploaded content such that dangerous file types can be accepted and placed in a location where the web server can execute them, enabling remote code execution when the uploaded payload is invoked.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a working Python exploit (CVE-2024-51791.py) and a README describing an unauthenticated (pre-auth/“0-click”) arbitrary file upload in a WordPress forms plugin, leading to RCE. Main exploit flow (CVE-2024-51791.py): - Takes --target (public form URL, e.g., http://host/form-1/) and --form-id (numeric form_id). - Sends a multipart/form-data POST to the provided form URL, uploading a file named cmd.php containing a simple PHP webshell. The file is attached under form field name "field-1" and is misleadingly labeled with MIME type application/pdf. - After upload, brute-forces the plugin’s upload directory structure under /wp-content/uploads/madeit-forms/<form_id>/<counter>/ by incrementing <counter> starting at form_id until it sees 5 consecutive 404s, tracking the last directory that returns HTTP 200. - Fetches the directory listing HTML and extracts the first .php link via regex href="...\.php" to determine the uploaded filename and build the final payload URL. - Performs a basic OS check by requesting the payload URL without parameters and looking for “windows” or “linux” in the response. - Provides an interactive loop that issues commands by GETing the payload URL with ?cmd=<command>, printing output. Capabilities: - Unauthenticated arbitrary file upload. - Automatic discovery of the uploaded payload location via directory enumeration. - Remote command execution via uploaded PHP webshell and interactive shell interface. Repository structure: - Top-level: CVE-2024-51791.py (primary exploit) and README.md (usage/instructions). - plugin/2.7.0/: large set of .svn/pristine files representing a snapshot of plugin/vendor code (PHP/JS/CSS/Composer artifacts). These files appear included for reference/analysis of the vulnerable plugin version rather than being executed by the exploit script. Notable implementation detail: base_url is derived using args.target.rstrip("/form-1/") which uses Python’s character-strip semantics (not substring removal). This can produce unexpected base_url values for some targets; however, the script’s intended behavior is to remove the trailing /form-1/ to reach the WordPress site root for constructing /wp-content/uploads/... paths.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.