TROYANOSYVIRUS
Voltar para CVEs

CVE-2022-3334

HIGH
7.2

Descricao

The Easy WP SMTP WordPress plugin before 1.5.0 unserialises the content of an imported file, which could lead to PHP object injection issue when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

Detalhes CVE

Pontuacao CVSS v3.17.2
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosHIGH
Interacao do usuarioNONE
Publicado10/31/2022
Ultima modificacao5/6/2025
Fontenvd
Avistamentos honeypot0

Produtos afetados

wp-ecommerce:easy_wp_smtp

Fraquezas (CWE)

CWE-502

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.