CVE Published: 19/04/2022 |
CVE Updated: 16/09/2024 |
CVE Year: 2022 Source: Patchstack |
Vendor: E4J s.r.l. |
Product: VikBooking Hotel Booking Engine & PMS (WordPress plugin) Status : PUBLISHED
CVE-2022-27862 Description
Arbitrary File Upload leading to RCE in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to upload and execute dangerous file types (e.g. PHP shell) via the signature upload on the booking form.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H