CVE-2022-4061 Vulnerability Details
/
/
/
CVE-2022-4061 Metadata Quick Info
CVE Published: 19/12/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022
Source: WPScan |
Vendor: Unknown |
Product: JobBoardWP
Status : PUBLISHED
CVE-2022-4061 Description
The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID:
CWE Name: CWE-434 Unrestricted Upload of File with Dangerous Type
Source: Unknown
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID:
CAPEC Description:
Source: NVD (National Vulnerability Database).