7.5
CVE-2022-4061
- EPSS 1.35%
- Veröffentlicht 19.12.2022 14:15:12
- Zuletzt bearbeitet 17.04.2025 14:15:24
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
JobBoardWP < 1.2.2 - Unauthenticated Arbitrary File Upload
JobBoardWP <= 1.2.1 - Unauthenticated Arbitrary File Upload
The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.
Mögliche Gegenmaßnahme
JobBoardWP – Job Board Listings and Submissions: Update to version 1.2.2, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ultimatemember ≫ Jobboardwp SwPlatformwordpress Version < 1.2.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
JobBoardWP – Job Board Listings and Submissions
Version
*-1.2.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.35% | 0.679 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
https://wpscan.com/vulnerability/fec68e6e-f612-43c8-8301-80f7ae3be665
https://www.wordfence.com/threat-intel/vulnerabilities/id/f816a32a-3c4d-447e-86a3-942b5e636cce