Логотип exploitDog
bind:CVE-2022-2711
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-2711

Количество 2

Количество 2

nvd логотип

CVE-2022-2711

больше 3 лет назад

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-fwj8-64xx-fwh9

больше 3 лет назад

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-2711

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-fwj8-64xx-fwh9

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not validating the paths of files contained in uploaded zip archives, allowing highly privileged users, such as admins, to write arbitrary files to any part of the file system accessible by the web server via a path traversal vector.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу