CVE-2022-2903
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
- Affected products
- Ninja Forms Contact Form
- Ninjaforms Ninja Forms
- < 3.6.13
- Fix
- Available
- CVSS 3.1
- 7.2 HIGH
- EPSS
- 1.2% (64th percentile)
- Weakness
- CWE-502
- NVD status
- Modified
- Published
- 2022-09-26
CVE-2022-2903 at NVD
1 known exploit for CVE-2022-2903
Proof-of-concept code and exploit modules indexed by Sploitus