The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12.
References
Configurations
History
02 May 2022, 19:34
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ninjaforms:ninja_forms_file_uploads:*:*:*:*:*:wordpress:*:* |
29 Mar 2022, 00:38
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:ninjaforms:ninja_forms:*:*:*:*:*:wordpress:*:* | |
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 6.1 |
References | (MISC) https://wordfence.com/vulnerability-advisories/#CVE-2022-0889 - Third Party Advisory | |
References | (MISC) https://ninjaforms.com/extensions/file-uploads/?changelog=1/#:~:text=3.3.13%20(30%20November%202021) - Release Notes, Vendor Advisory |
23 Mar 2022, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-03-23 20:15
Updated : 2024-02-04 22:29
NVD link : CVE-2022-0889
Mitre link : CVE-2022-0889
CVE.ORG link : CVE-2022-0889
JSON object : View
Products Affected
ninjaforms
- ninja_forms_file_uploads
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')