110 lines
4.0 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2022-0316",
"sourceIdentifier": "contact@wpscan.com",
"published": "2023-01-23T15:15:13.703",
"lastModified": "2023-11-07T03:41:12.380",
"vulnStatus": "Modified",
2023-04-24 12:24:31 +02:00
"descriptions": [
{
"lang": "en",
"value": "The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
]
},
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:aidreform_project:aidreform:-:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "349B3C5A-3C95-4C80-9C09-DCFE002CB048"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:chimpgroup:bolster:-:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "CD32D146-AE32-4F24-BB13-034D0BCEE102"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:chimpgroup:spikes:-:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "692D91D4-FE19-4C7B-A0C2-8ADFF4EF3DA0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:chimpgroup:westand:*:*:*:*:*:wordpress:*:*",
"versionEndExcluding": "2.1",
"matchCriteriaId": "82C6F1C1-034D-41D4-B1B0-E97E860F60BE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:club-theme_project:club-theme:-:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "62CF701B-A5BF-4A80-A1DA-D7BD3DCC62B3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:footysquare_project:footysquare:-:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "E8492E39-28B9-4291-86A9-CA7C883EA483"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:pixfill:kings_club:-:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "241E870E-DBF9-442A-A2E8-335375EB3995"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:soundblast_project:soundblast:-:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "8E8B3706-CC83-422D-8F3E-35E454B25C9B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:spikes-black_project:spikes-black:-:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "F95938E5-CC29-453F-8C22-0AF971A7CE76"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:statfort_project:statfort:-:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "B9E2332D-410F-4765-8C6E-6A0FB07795CE"
}
]
}
]
}
],
"references": [
{
"url": "https://wpscan.com/vulnerability/9ab3d6cf-aad7-41bc-9aae-dc5313f12f7c",
"source": "contact@wpscan.com",
"tags": [
"Exploit",
"Third Party Advisory"
]
}
]
}