From 432fbfeec814a67ef408d6750cd9c11cb2f641c5 Mon Sep 17 00:00:00 2001 From: Goby <50955360+gobysec@users.noreply.github.com> Date: Tue, 23 May 2023 15:35:04 +0800 Subject: [PATCH] Create CVE-2022-2544.md add CVE-2022-2544 --- CVE-2022-2544.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 CVE-2022-2544.md diff --git a/CVE-2022-2544.md b/CVE-2022-2544.md new file mode 100644 index 0000000..db410a7 --- /dev/null +++ b/CVE-2022-2544.md @@ -0,0 +1,12 @@ +## Wordpress wpjobboard plugin wpjobboard directory traversal vulnerability (CVE-2022-2544) + +| **Vulnerability** | **Wordpress wpjobboard plugin wpjobboard directory traversal vulnerability (CVE-2022-2544)** | +| :----: | :-----| +| **Chinese name** | Wordpress wpjobboard 插件 wpjobboard 页面目录遍历漏洞(CVE-2022-2544) | +| **CVSS core** | 7.5 | +| **FOFA Query** (click to view the results directly)| [body="wp-content/plugins/wpjobboard"](https://en.fofa.info/result?qbase64=Ym9keT0id3AtY29udGVudC9wbHVnaW5zL3dwam9iYm9hcmQi) | +| **Number of assets affected** | 1201 | +| **Description** | Wpjobboard is a plugin of Wordpress. The Wpjobboard plug-in allows website owners to embed payment forms and make payments via Visa, American Express, Discover and Mastercard through their Click&Lead merchant accounts.The Wpjobboard plug-in has a directory traversal vulnerability, through which an attacker can view sensitive directories and files in the server, control the entire system, and finally cause the system to be in an extremely insecure state. | +| **Impact** | The Wpjobboard plug-in has a directory traversal vulnerability, through which an attacker can view sensitive directories and files in the server, control the entire system, and finally cause the system to be in an extremely insecure state. | + +![](https://s3.bmp.ovh/imgs/2023/05/23/4ddb35a567453502.gif)