Lucene search

K
cve[email protected]CVE-2022-1777
HistoryJun 13, 2022 - 1:15 p.m.

CVE-2022-1777

2022-06-1313:15:12
CWE-862
web.nvd.nist.gov
49
3
cve-2022-1777
filr wordpress plugin
authorization check
ajax actions
nonce leakage
html file upload
file deletion

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%

The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX actions, allowing them to be called by any authenticated users, such as subscriber. They are are protected with a nonce, however the nonce is leaked on the dashboard. This could allow them to upload arbitrary HTML files as well as delete all files or arbitrary ones.

Affected configurations

Vulners
NVD
Node
dmxreadysecure_document_libraryRange<1.2.2.1
VendorProductVersionCPE
dmxreadysecure_document_library*cpe:2.3:a:dmxready:secure_document_library:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Filr – Secure document library",
    "vendor": "Unknown",
    "versions": [
      {
        "lessThan": "1.2.2.1",
        "status": "affected",
        "version": "1.2.2.1",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

43.0%