7.5
CVE-2022-4061
- EPSS 19.91%
- Veröffentlicht 19.12.2022 14:15:12
- Zuletzt bearbeitet 17.04.2025 14:15:24
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
JobBoardWP <= 1.2.1 - Unauthenticated Arbitrary File Upload
The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.
Mögliche Gegenmaßnahme
JobBoardWP – Job Board Listings and Submissions: Update to version 1.2.2, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
JobBoardWP – Job Board Listings and Submissions
Version
* - 1.2.1
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ultimatemember ≫ Jobboardwp SwPlatformwordpress Version < 1.2.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 19.91% | 0.952 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|