Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-2180
HistoryAug 15, 2022 - 11:21 a.m.

Cross site request forgery (csrf)

2022-08-1511:21:00
PRIOn knowledge base
www.prio-n.com
2
wordpress
greyd.suite
file upload
remote code execution
cross site request forgery

9.9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.1%

The GREYD.SUITE WordPress theme does not properly validate uploaded custom font packages, and does not perform any authorization or csrf checks, allowing an unauthenticated attacker to upload arbitrary files including php source files, leading to possible remote code execution (RCE).

CPENameOperatorVersion
greyd.suitelt1.2.7

9.9 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.1%

Related for PRION:CVE-2022-2180