CVE-2022-4298Path Traversal in Wholesale Market

Severity
9.8CRITICALNVD
EPSS
55.7%
top 1.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateJan 3

Description

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-r9x2-m498-v92q: The Wholesale Market WordPress plugin before 22023-01-03
CVEList
Wholesale Market < 2.2.1 - Unauthenticated Arbitrary File Download2023-01-02

📋Vendor Advisories

1
Juniper
CVE-2022-22249: An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series a2022-10-18
CVE-2022-4298 — Path Traversal in Wholesale Market | cvebase