TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2022-4328

CRITICAL
9.8

Beschreibung

The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht3/6/2023
Zuletzt geandert3/4/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

najeebmedia:woocommerce_checkout_field_manager

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.