Update CVE-2022-1574.yaml

patch-1
Ritik Chaddha 2022-10-19 16:01:41 +05:30 committed by GitHub
parent 43f78562f8
commit fed01983f8
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 2 deletions

View File

@ -8,13 +8,13 @@ info:
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server.
reference:
- https://wpscan.com/vulnerability/c36d0ea8-bf5c-4af9-bd3d-911eb02adc14
- https://nvd.nist.gov/vuln/detail/CVE-2022-1574
- https://wordpress.org/plugins/html2wp/
- https://nvd.nist.gov/vuln/detail/CVE-2022-1574
classification:
cve-id: CVE-2022-1574
metadata:
verified: true
tags: cve,cve2022,wordpress,wp-plugin,wp,fileupload,wpscan,unauthenticated
tags: cve,cve2022,wordpress,wp-plugin,wp,fileupload,unauth,html2wp
requests:
- raw: