The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable WordPress sites, in versions up to and including 3.3.12.
References
Configurations
History
11 Jan 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
07 Nov 2023, 03:41
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2022-03-23 20:15
Updated : 2024-02-28 19:09
NVD link : CVE-2022-0889
Mitre link : CVE-2022-0889
CVE.ORG link : CVE-2022-0889
JSON object : View
Products Affected
ninjaforms
- ninja_forms_file_uploads
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')