mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-06-01 19:21:37 +00:00
122 lines
4.2 KiB
JSON
122 lines
4.2 KiB
JSON
{
|
|
"id": "CVE-2022-0316",
|
|
"sourceIdentifier": "contact@wpscan.com",
|
|
"published": "2023-01-23T15:15:13.703",
|
|
"lastModified": "2023-01-31T18:30:44.070",
|
|
"vulnStatus": "Analyzed",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "NONE",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "HIGH",
|
|
"integrityImpact": "HIGH",
|
|
"availabilityImpact": "HIGH",
|
|
"baseScore": 9.8,
|
|
"baseSeverity": "CRITICAL"
|
|
},
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 5.9
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "contact@wpscan.com",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-434"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:aidreform_project:aidreform:-:*:*:*:*:wordpress:*:*",
|
|
"matchCriteriaId": "349B3C5A-3C95-4C80-9C09-DCFE002CB048"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:chimpgroup:bolster:-:*:*:*:*:wordpress:*:*",
|
|
"matchCriteriaId": "CD32D146-AE32-4F24-BB13-034D0BCEE102"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:chimpgroup:spikes:-:*:*:*:*:wordpress:*:*",
|
|
"matchCriteriaId": "692D91D4-FE19-4C7B-A0C2-8ADFF4EF3DA0"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:chimpgroup:westand:*:*:*:*:*:wordpress:*:*",
|
|
"versionEndExcluding": "2.1",
|
|
"matchCriteriaId": "82C6F1C1-034D-41D4-B1B0-E97E860F60BE"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:club-theme_project:club-theme:-:*:*:*:*:wordpress:*:*",
|
|
"matchCriteriaId": "62CF701B-A5BF-4A80-A1DA-D7BD3DCC62B3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:footysquare_project:footysquare:-:*:*:*:*:wordpress:*:*",
|
|
"matchCriteriaId": "E8492E39-28B9-4291-86A9-CA7C883EA483"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:pixfill:kings_club:-:*:*:*:*:wordpress:*:*",
|
|
"matchCriteriaId": "241E870E-DBF9-442A-A2E8-335375EB3995"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:soundblast_project:soundblast:-:*:*:*:*:wordpress:*:*",
|
|
"matchCriteriaId": "8E8B3706-CC83-422D-8F3E-35E454B25C9B"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:spikes-black_project:spikes-black:-:*:*:*:*:wordpress:*:*",
|
|
"matchCriteriaId": "F95938E5-CC29-453F-8C22-0AF971A7CE76"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:statfort_project:statfort:-:*:*:*:*:wordpress:*:*",
|
|
"matchCriteriaId": "B9E2332D-410F-4765-8C6E-6A0FB07795CE"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://wpscan.com/vulnerability/9ab3d6cf-aad7-41bc-9aae-dc5313f12f7c",
|
|
"source": "contact@wpscan.com",
|
|
"tags": [
|
|
"Exploit",
|
|
"Third Party Advisory"
|
|
]
|
|
}
|
|
]
|
|
} |