Логотип exploitDog
bind:CVE-2022-4298
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-4298

Количество 2

Количество 2

nvd логотип

CVE-2022-4298

около 3 лет назад

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-r9x2-m498-v92q

около 3 лет назад

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-4298

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVSS3: 9.8
56%
Средний
около 3 лет назад
github логотип
GHSA-r9x2-m498-v92q

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVSS3: 9.8
56%
Средний
около 3 лет назад

Уязвимостей на страницу