4.9
CVE-2022-2046
- EPSS 0.28%
- Veröffentlicht 08.08.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 07:00:13
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Directorist <= 7.2.2 - Authenticated (Admin+) Arbitrary File Upload
The Directorist WordPress plugin before 7.2.3 allows administrators to download other plugins from the same vendor directly to the site, but does not check the URL domain it gets the zip files from. This could allow administrators to run code on the server, which is a problem in multisite configurations.
Mögliche Gegenmaßnahme
Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings: Update to version 7.2.3, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings
Version
* - 7.2.2
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wpwax ≫ Directorist SwPlatformwordpress Version < 7.2.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.28% | 0.507 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.