Sploitus

CVE-2022-2903

1 known exploit for CVE-2022-2903

The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

Affected products
Ninja Forms Contact Form
Ninjaforms Ninja Forms
< 3.6.13
Fix
Available
CVSS 3.1
7.2 HIGH
EPSS
1.2% (64th percentile)
Weakness
CWE-502
NVD status
Modified
Published
2022-09-26
CVE-2022-2903 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2022-2903

Proof-of-concept code and exploit modules indexed by Sploitus