CVE-2022-2544 Vulnerability Details
/
/
/
CVE-2022-2544 Metadata Quick Info
CVE Published: 22/08/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022
Source: WPScan |
Vendor: Unknown |
Product: Ninja Job Board – Ultimate WordPress Job Board Plugin
Status : PUBLISHED
CVE-2022-2544 Description
The Ninja Job Board WordPress plugin before 1.3.3 does not protect the directory where it stores uploaded resumes, making it vulnerable to unauthenticated Directory Listing which allows the download of uploaded resumes.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-425
CWE Name: CWE-425 Direct Request (
Forced Browsing
)
Source: Unknown
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).