CVE-2022-2903
Summary
| CVE | CVE-2022-2903 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-26 13:15:00 UTC |
| Updated | 2022-09-28 17:34:00 UTC |
| Description | The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| NinjaForms < 3.6.13 - Admin+ PHP Objection Injection WordPress Security Vulnerability |
MISC |
wpscan.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Alessio Santoru
Legacy QID Mappings
- 150638 WordPress Ninja Forms Plugin: Deserialization Vulnerability (CVE-2022-2903)