Логотип exploitDog
bind:CVE-2022-4047
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-4047

Количество 2

Количество 2

nvd логотип

CVE-2022-4047

около 3 лет назад

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-3j85-6864-55p3

около 3 лет назад

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-4047

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVSS3: 9.8
73%
Высокий
около 3 лет назад
github логотип
GHSA-3j85-6864-55p3

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVSS3: 9.8
73%
Высокий
около 3 лет назад

Уязвимостей на страницу