The JobBoardWP WordPress plugin before 1.2.2 does not properly validate file names and types in its file upload functionalities, allowing unauthenticated users to upload arbitrary files such as PHP.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-12-19T13:41:42.453Z

Updated:

Reserved: 2022-11-18T18:44:27.247Z


Link: CVE-2022-4061

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2022-12-19T14:15:12.013

Modified: 2023-11-07T03:56:50.187


Link: CVE-2022-4061

JSON object: View

cve-icon Redhat Information

No data.

CWE

No CWE.