The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/fec68e6e-f612-43c8-8301-80f7ae3be665 | Exploit Third Party Advisory |
| https://wpscan.com/vulnerability/fec68e6e-f612-43c8-8301-80f7ae3be665 | Exploit Third Party Advisory |
Configurations
History
21 Nov 2024, 07:34
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://wpscan.com/vulnerability/fec68e6e-f612-43c8-8301-80f7ae3be665 - Exploit, Third Party Advisory |
07 Nov 2023, 03:56
| Type | Values Removed | Values Added |
|---|---|---|
| CWE |
Information
Published : 2022-12-19 14:15
Updated : 2025-04-17 14:15
NVD link : CVE-2022-4061
Mitre link : CVE-2022-4061
CVE.ORG link : CVE-2022-4061
JSON object : View
Products Affected
ultimatemember
- jobboardwp
CWE
No CWE.
