Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3gqc-3hvh-6hcg

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php.

admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php.

EPSS

Процентиль: 90%
0.05847
Низкий

7.2 High

CVSS3

Дефекты

CWE-1321
CWE-915

Связанные уязвимости

CVSS3: 7.2
nvd
около 8 лет назад

admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php.

EPSS

Процентиль: 90%
0.05847
Низкий

7.2 High

CVSS3

Дефекты

CWE-1321
CWE-915