Логотип exploitDog
bind:CVE-2022-0687
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-0687

Количество 2

Количество 2

nvd логотип

CVE-2022-0687

почти 4 года назад

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-588c-3c3h-7vcq

почти 4 года назад

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-0687

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-588c-3c3h-7vcq

The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users with the custom "Amelia Manager" role.

CVSS3: 8.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу