Логотип exploitDog
bind:CVE-2022-0499
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-0499

Количество 2

Количество 2

nvd логотип

CVE-2022-0499

почти 4 года назад

The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-j8w4-5x7j-f9rc

почти 4 года назад

The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-0499

The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

CVSS3: 8.8
0%
Низкий
почти 4 года назад
github логотип
GHSA-j8w4-5x7j-f9rc

The Sermon Browser WordPress plugin through 0.45.22 does not have CSRF checks in place when uploading Sermon files, and does not validate them in any way, allowing attackers to make a logged in admin upload arbitrary files such as PHP ones.

CVSS3: 8.8
0%
Низкий
почти 4 года назад

Уязвимостей на страницу