Tag
Unauthenticated attackers can achieve arbitrary recursive directory deletion in Super Forms versions 6.3.316 and earlier by exploiting improper path validation in the submit_form function.