Open Forms is an application for creating and publishing smart forms. Open Forms supports file uploads as one of the form field types. These fields can be configured to allow only certain file extensions to be uploaded by end users (e.g. only PDF / Excel / ...). The input validation of uploaded files is insufficient in versions prior to 1.0.9 and 1.1.1. Users could alter or strip file extensions to bypass this validation. This results in files being uploaded to the server that are of a different file type than indicated by the file name extension. These files may be downloaded (manually or automatically) by staff and/or other applications for further processing. Malicious files can therefore find their way into internal/trusted networks. Versions 1.0.9 and 1.1.1 contain patches for this issue. As a workaround, an API gateway or intrusion detection solution in front of open-forms may be able to scan for and block malicious content before it reaches the Open Forms application.
総合評価: CVE-2022-31041 は中リスク(48.1/100)。CVSS 深刻度は高。悪用される可能性が高い(EPSS 0.73%、49 パーセンタイル) 推奨対応: 影響資産を整理し、修補計画に組み込んでください。
リスクは変動します。再評価に基づき、本ページの表示内容を更新しています。
EPSS は日次で悪用されやすさの相対度合いを推定します。パーセンタイルは採点済み CVE の中での相対位置(高いほど相対的に深刻)を示します。
| # | 日付 | 旧 EPSS スコア | 新 EPSS スコア | Δ(新 − 旧) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.24% | 0.73% | +0.49% |
| 2 | 2025-06-14 | 0.04% | 0.24% | +0.20% |
| 3 | 2025-03-30 | — | 0.04% | — |
EPSS の全履歴 (全 8 件)
この CVE の CVSS 指標。
| ベーススコア | バージョン | 深刻度 | ベクトル | 悪用しやすさ | 影響 | スコアの出典 |
|---|---|---|---|---|---|---|
| 7.6 | 3.1 | HIGH |
|
2.8 | 4.7 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
| 4.0 | 2.0 | MEDIUM |
|
8.0 | 2.9 | [email protected] |
| ベンダー | 製品 | バージョン | 生の CPE |
|---|---|---|---|
| maykinmedia | open_forms | < 1.0.9 | cpe:2.3:a:maykinmedia:open_forms:*:*:*:*:*:*:*:* |
| maykinmedia | open_forms | 1.1.0 | cpe:2.3:a:maykinmedia:open_forms:1.1.0:-:*:*:*:*:*:* |
| maykinmedia | open_forms | 1.1.0 | cpe:2.3:a:maykinmedia:open_forms:1.1.0:rc0:*:*:*:*:*:* |
| maykinmedia | open_forms | 1.1.0 | cpe:2.3:a:maykinmedia:open_forms:1.1.0:rc1:*:*:*:*:*:* |
| URL | タグ |
|---|---|
| https://github.com/open-formulieren/open-forms/commit/0978a29e821a7228c5d46c0527c3e925eb91b071 | Patch Third Party Advisory |
| https://github.com/open-formulieren/open-forms/security/advisories/GHSA-h85r-xv4w-cg8g | Third Party Advisory |