CVE Published: 23/03/2022 |
CVE Updated: 02/08/2024 |
CVE Year: 2022 Source: Wordfence |
Vendor: SaturdayDrive |
Product: Ninja Forms - File Uploads Status : PUBLISHED
CVE-2022-0889 Description
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12.
Metrics
CVSS Version: 3.1 |
Base Score: 7.2 HIGH Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N