7.2
CVE-2022-4323
- EPSS 0.86%
- Veröffentlicht 23.01.2023 15:15:14
- Zuletzt bearbeitet 02.04.2025 15:15:49
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Google Analyticator <= 6.5.5 - Authenticated (Administrator+) PHP Object Injection
The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present
Mögliche Gegenmaßnahme
Analyticator: Update to version 6.5.6, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Analyticator
Version
*-6.5.5
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sumo ≫ Google Analyticator SwPlatformwordpress Version < 6.5.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.86% | 0.745 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.2 | 1.2 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|