9.8

CVE-2022-3921

Exploit

Listingo < 3.2.7 - Unauthenticated Arbitrary File Upload

Listingo <= 3.2.5 - Unauthenticated Arbitrary File Upload

The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
Mögliche Gegenmaßnahme
Listingo: Update to version 3.2.7, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ThemographicsListingo SwPlatformwordpress Version < 3.2.7
Weitere Schwachstelleninformationen
SystemWordPress Theme
Produkt Listingo
Version *-3.2.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 21.21% 0.973
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://wpscan.com/vulnerability/e39b59b0-f24f-4de5-a21c-c4de34c3a14f
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/62bc53ae-7cdb-491c-a315-5bf8fa80c27b
Third Party Advisory