9.8
CVE-2022-3921
- EPSS 8.91%
- Veröffentlicht 12.12.2022 18:15:11
- Zuletzt bearbeitet 22.04.2025 15:16:01
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Listingo <= 3.2.5 - Unauthenticated Arbitrary File Upload
The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE
Mögliche Gegenmaßnahme
Listingo: Update to version 3.2.7, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Theme
≫
Produkt
Listingo
Version
*-3.2.5
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Themographics ≫ Listingo SwPlatformwordpress Version < 3.2.7
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.91% | 0.923 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|