mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-12 02:04:49 +00:00
70 lines
2.1 KiB
JSON
70 lines
2.1 KiB
JSON
{
|
|
"id": "CVE-2022-3921",
|
|
"sourceIdentifier": "contact@wpscan.com",
|
|
"published": "2022-12-12T18:15:11.970",
|
|
"lastModified": "2023-11-07T03:51:57.957",
|
|
"vulnStatus": "Modified",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE"
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "El tema de WordPress Listingo anterior a 3.2.7 no valida los archivos que se cargar\u00e1n mediante una acci\u00f3n AJAX disponible para usuarios no autenticados, lo que podr\u00eda permitirles cargar archivos arbitrarios y conducir a RCE."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "HIGH",
|
|
"availabilityImpact": "HIGH",
|
|
"baseScore": 9.8,
|
|
"baseSeverity": "CRITICAL"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 5.9
|
|
}
|
|
]
|
|
},
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:themographics:listingo:*:*:*:*:*:wordpress:*:*",
|
|
"versionEndExcluding": "3.2.7",
|
|
"matchCriteriaId": "D9C6DCEE-06D7-4779-9787-5A76CD4A82F7"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://wpscan.com/vulnerability/e39b59b0-f24f-4de5-a21c-c4de34c3a14f",
|
|
"source": "contact@wpscan.com",
|
|
"tags": [
|
|
"Exploit",
|
|
"Third Party Advisory"
|
|
]
|
|
}
|
|
]
|
|
} |