| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24833 | Hig | 0.46 | 8.2 | 0.01 | Apr 11, 2022 | PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of the project, which was at the… | ||
| CVE-2022-24832 | Hig | 0.00 | 8.2 | 0.02 | Apr 11, 2022 | GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly escape special characters when using the username to construct LDAP queries. While this does not directly allow arbitrary LDAP data… | ||
| CVE-2022-24827 | Hig | 0.00 | 8.1 | 0.01 | Apr 11, 2022 | Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the following together: Elide Aggregation Data Store for Analytic Queries, Parameterized Columns (A column that requires a client provided parameter), and a… | ||
| CVE-2022-27838 | Hig | 0.50 | 7.7 | 0.00 | Apr 11, 2022 | Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege. | ||
| CVE-2022-27836 | Hig | 0.55 | 8.4 | 0.00 | Apr 11, 2022 | Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary… | ||
| CVE-2022-27835 | Hig | 0.49 | 7.6 | 0.00 | Apr 11, 2022 | Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write. | ||
| CVE-2022-27830 | Hig | 0.55 | 8.5 | 0.00 | Apr 11, 2022 | Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-27829 | Hig | 0.55 | 8.5 | 0.00 | Apr 11, 2022 | Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-27828 | Hig | 0.55 | 8.5 | 0.00 | Apr 11, 2022 | Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-27827 | Hig | 0.55 | 8.5 | 0.00 | Apr 11, 2022 | Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-27826 | Hig | 0.55 | 8.5 | 0.00 | Apr 11, 2022 | Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities. | ||
| CVE-2022-27578 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2022 | An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content. | ||
| CVE-2022-27572 | Hig | 0.53 | 8.1 | 0.01 | Apr 11, 2022 | Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers. | ||
| CVE-2022-27571 | Hig | 0.53 | 8.1 | 0.01 | Apr 11, 2022 | Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker. | ||
| CVE-2022-27570 | Hig | 0.53 | 8.1 | 0.01 | Apr 11, 2022 | Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker. | ||
| CVE-2022-27569 | Hig | 0.53 | 8.1 | 0.01 | Apr 11, 2022 | Heap-based buffer overflow vulnerability in parser_infe function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker. | ||
| CVE-2022-27568 | Hig | 0.53 | 8.1 | 0.01 | Apr 11, 2022 | Heap-based buffer overflow vulnerability in parser_iloc function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker. | ||
| CVE-2022-27528 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2022 | A maliciously crafted DWFX and SKP files in Autodesk Navisworks 2022 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. | ||
| CVE-2022-26098 | Hig | 0.53 | 8.1 | 0.01 | Apr 11, 2022 | Heap-based buffer overflow vulnerability in sheifd_create function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers. | ||
| CVE-2022-26092 | Hig | 0.48 | 7.4 | 0.00 | Apr 11, 2022 | Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution. | ||
| CVE-2022-25796 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2022 | A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks 2022 within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | ||
| CVE-2022-25794 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2022 | An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.2 and prior may lead to code execution through maliciously crafted ActionScript Byte Code 'ABC' files or information disclosure. ABC files are created by the Flash compiler and contain executable code. This… | ||
| CVE-2022-25792 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2022 | A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code. | ||
| CVE-2022-25791 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2022 | A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files. | ||
| CVE-2022-25790 | Hig | 0.51 | 7.8 | 0.01 | Apr 11, 2022 | A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution. | ||
| CVE-2022-25789 | Hig | 0.51 | 7.8 | 0.02 | Apr 11, 2022 | A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution. | ||
| CVE-2022-24829 | Hig | 0.00 | 8.1 | 0.01 | Apr 11, 2022 | Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes this allows for an attacker to gain access to the application erroneously. The configuration is leaked… | ||
| CVE-2022-24815 | Hig | 0.46 | 8.1 | 0.01 | Apr 11, 2022 | JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice architectures. SQL Injection vulnerability in entities for applications generated with the option "reactive with Spring WebFlux" enabled and an SQL database using… | ||
| CVE-2022-22964 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2022 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file. | ||
| CVE-2022-22962 | Hig | 0.51 | 7.8 | 0.00 | Apr 11, 2022 | VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file. | ||
| CVE-2022-22572 | Hig | 0.57 | 8.8 | 0.02 | Apr 11, 2022 | A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1. | ||
| CVE-2022-22257 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity. | ||
| CVE-2022-22256 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-22255 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability. | ||
| CVE-2022-22254 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2022-22253 | Hig | 0.49 | 7.5 | 0.00 | Apr 11, 2022 | The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vulnerability may affect system stability. | ||
| CVE-2022-1316 | Hig | 0.00 | 8.8 | 0.00 | Apr 11, 2022 | Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation | ||
| CVE-2022-1262 | Hig | 0.51 | 7.8 | 0.02 | Apr 11, 2022 | A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root. | ||
| CVE-2022-0999 | Hig | 0.57 | 8.8 | 0.01 | Apr 11, 2022 | An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior. | ||
| CVE-2022-0835 | Hig | 0.53 | 8.1 | 0.00 | Apr 11, 2022 | AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user. | ||
| CVE-2021-4047 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9. | ||
| CVE-2021-46740 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-40065 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality. | ||
| CVE-2021-43442 | Hig | 0.53 | 8.1 | 0.01 | Apr 11, 2022 | A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 151106 (Ax68), and V5.0.9 build 150615 (Ax78) due to a failure to allow the creation of more than one administrator account; however, this can be bypassed by… | ||
| CVE-2021-38930 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331. | ||
| CVE-2021-38929 | Hig | 0.49 | 7.5 | 0.01 | Apr 11, 2022 | IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330. | ||
| CVE-2021-37292 | Hig | 0.47 | 7.2 | 0.07 | Apr 11, 2022 | An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control. | ||
| CVE-2021-40219 | — | Hig | 0.57 | 8.8 | 0.03 | Apr 11, 2022 | Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution. | |
| CVE-2022-1023 | Hig | 0.47 | 7.2 | 0.01 | Apr 11, 2022 | The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file | ||
| CVE-2022-1008 | Hig | 0.47 | 7.2 | 0.02 | Apr 11, 2022 | The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed |
- risk 0.46cvss 8.2epss 0.01
PrivateBin is minimalist, open source online pastebin clone where the server has zero knowledge of pasted data. In PrivateBin < v1.4.0 a cross-site scripting (XSS) vulnerability was found. The vulnerability is present in all versions from v0.21 of the project, which was at the…
- risk 0.00cvss 8.2epss 0.02
GoCD is an open source a continuous delivery server. The bundled gocd-ldap-authentication-plugin included with the GoCD Server fails to correctly escape special characters when using the username to construct LDAP queries. While this does not directly allow arbitrary LDAP data…
- risk 0.00cvss 8.1epss 0.01
Elide is a Java library that lets you stand up a GraphQL/JSON-API web service with minimal effort. When leveraging the following together: Elide Aggregation Data Store for Analytic Queries, Parameterized Columns (A column that requires a client provided parameter), and a…
- risk 0.50cvss 7.7epss 0.00
Improper access control vulnerability in FactoryCamera prior to version 2.1.96 allows attacker to access the file with system privilege.
- risk 0.55cvss 8.4epss 0.00
Improper access control and path traversal vulnerability in Storage Manager and Storage Manager Service prior to SMR Apr-2022 Release 1 allow local attackers to access arbitrary system files without a proper permission. The patch adds proper validation logic to prevent arbitrary…
- risk 0.49cvss 7.6epss 0.00
Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in MediaMonitorEvent prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in MediaMonitorDimension prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
- risk 0.55cvss 8.5epss 0.00
Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.
- risk 0.51cvss 7.8epss 0.00
An attacker can perform a privilege escalation through the SICK OEE if the application is installed in a directory where non authenticated or low privilege users can modify its content.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow vulnerability in parser_ipma function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow vulnerability in sheifd_get_info_image function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow vulnerability in parser_single_iref function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow vulnerability in parser_infe function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow vulnerability in parser_iloc function in libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attacker.
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted DWFX and SKP files in Autodesk Navisworks 2022 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
- risk 0.53cvss 8.1epss 0.01
Heap-based buffer overflow vulnerability in sheifd_create function of libsimba library prior to SMR Apr-2022 Release 1 allows code execution by remote attackers.
- risk 0.48cvss 7.4epss 0.00
Improper boundary check in Quram Agif library prior to SMR Apr-2022 Release 1 allows arbitrary code execution.
- risk 0.51cvss 7.8epss 0.01
A Double Free vulnerability allows remote malicious actors to execute arbitrary code on DWF file in Autodesk Navisworks 2022 within affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
- risk 0.51cvss 7.8epss 0.01
An Out-Of-Bounds Read Vulnerability in Autodesk FBX Review version 1.5.2 and prior may lead to code execution through maliciously crafted ActionScript Byte Code 'ABC' files or information disclosure. ABC files are created by the Flash compiler and contain executable code. This…
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted DXF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated buffer through Buffer overflow vulnerability. This vulnerability can be exploited to execute arbitrary code.
- risk 0.51cvss 7.8epss 0.01
A Memory Corruption vulnerability for DWF and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 may lead to code execution through maliciously crafted DLL files.
- risk 0.51cvss 7.8epss 0.01
A maliciously crafted DWF file in Autodesk AutoCAD 2022, 2021, 2020, 2019 and Autodesk Navisworks 2022 can be used to write beyond the allocated boundaries when parsing the DWF files. Exploitation of this vulnerability may lead to code execution.
- risk 0.51cvss 7.8epss 0.02
A maliciously crafted DWF, 3DS and DWFX files in Autodesk AutoCAD 2022, 2021, 2020, 2019 can be used to trigger use-after-free vulnerability. Exploitation of this vulnerability may lead to code execution.
- risk 0.00cvss 8.1epss 0.01
Garden is an automation platform for Kubernetes development and testing. In versions prior to 0.12.39 multiple endpoints did not require authentication. In some operating modes this allows for an attacker to gain access to the application erroneously. The configuration is leaked…
- risk 0.46cvss 8.1epss 0.01
JHipster is a development platform to quickly generate, develop, & deploy modern web applications & microservice architectures. SQL Injection vulnerability in entities for applications generated with the option "reactive with Spring WebFlux" enabled and an SQL database using…
- risk 0.51cvss 7.8epss 0.00
VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file.
- risk 0.51cvss 7.8epss 0.00
VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file.
- risk 0.57cvss 8.8epss 0.02
A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects Incapptic Connect version < 1.40.1.
- risk 0.49cvss 7.5epss 0.01
The customization framework has a vulnerability of improper permission control.Successful exploitation of this vulnerability may affect data integrity.
- risk 0.49cvss 7.5epss 0.01
The DFX module has an access control vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The application framework has a common DoS vulnerability.Successful exploitation of this vulnerability may affect the availability.
- risk 0.49cvss 7.5epss 0.01
A permission bypass vulnerability exists when the NFC CAs access the TEE.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.00
The DFX module has a vulnerability of improper validation of integrity check values.Successful exploitation of this vulnerability may affect system stability.
- risk 0.00cvss 8.8epss 0.00
Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation
- risk 0.51cvss 7.8epss 0.02
A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.
- risk 0.57cvss 8.8epss 0.01
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
- risk 0.53cvss 8.1epss 0.00
AVEVA System Platform 2020 stores sensitive information in cleartext, which may allow access to an attacker or a low-privileged user.
- risk 0.49cvss 7.5epss 0.01
The release of OpenShift 4.9.6 included four CVE fixes for the haproxy package, however the patch for CVE-2021-39242 was missing. This issue only affects Red Hat OpenShift 4.9.
- risk 0.49cvss 7.5epss 0.01
The device authentication service module has a defect vulnerability introduced in the design process.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.49cvss 7.5epss 0.01
The communication module has a service logic error vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
- risk 0.53cvss 8.1epss 0.01
A Logic Flaw vulnerability exists in i3 International Inc Annexxus Camera V5.2.0 build 150317 (Ax46), V5.0.9 build 151106 (Ax68), and V5.0.9 build 150615 (Ax78) due to a failure to allow the creation of more than one administrator account; however, this can be bypassed by…
- risk 0.49cvss 7.5epss 0.01
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331.
- risk 0.49cvss 7.5epss 0.01
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330.
- risk 0.47cvss 7.2epss 0.07
An Access Control vulnerability exists in KevinLAB Inc Building Energy Management System 4ST BEMS 1.0.0 due to an undocumented backdoor account. A malicious user can log in using the backdor account with admin highest privileges and obtain system control.
- risk 0.57cvss 8.8epss 0.03
Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.
- risk 0.47cvss 7.2epss 0.01
The Podcast Importer SecondLine WordPress plugin before 1.3.8 does not sanitise and properly escape some imported data, which could allow SQL injection attacks to be performed by imported a malicious podcast file
- risk 0.47cvss 7.2epss 0.02
The One Click Demo Import WordPress plugin before 3.1.0 does not validate the imported file, allowing high privilege users such as admin to upload arbitrary files (such as PHP) even when FILE_MODS and FILE_EDIT are disallowed