9.8
CVE-2022-4328
- EPSS 80.25%
- Veröffentlicht 06.03.2023 14:15:09
- Zuletzt bearbeitet 04.03.2025 20:15:35
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
WooCommerce Checkout Field Manager <= 17.3 - Unauthenticated Arbitrary File Upload
The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server
Mögliche Gegenmaßnahme
WooCommerce Checkout Field Manager: Update to version 18.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WooCommerce Checkout Field Manager
Version
*-17.3
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Najeebmedia ≫ Woocommerce Checkout Field Manager SwPlatformwordpress Version < 18.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 80.25% | 0.991 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|