CVE-2022-4171
CVSS V2 None
CVSS V3 None
Description
The demon image annotation plugin for WordPress is vulnerable to improper input validation in versions up to, and including 5.0. This is due to the plugin improperly validating the number of characters supplied during an annotation despite there being a setting to limit the number characters input. This means that unauthenticated attackers can bypass the length restrictions and input more characters than allowed via the settings.
Overview
- CVE ID
- CVE-2022-4171
- Assigner
- security@wordfence.com
- Vulnerability Status
- Analyzed
- Published Version
- 2022-12-13T21:15:11
- Last Modified Date
- 2022-12-16T18:25:35
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:superwhite:demon_image_annotation:*:*:*:*:*:wordpress:*:* | 1 | OR | 5.0 |
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2022-4171 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4171 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2022-12-13 22:14:53 | Added to TrackCVE | |||
2022-12-14 14:15:17 | 2022-12-13T21:15:11.870 | 2022-12-13T21:15:11 | CVE Published Date | updated |
2022-12-14 14:15:17 | 2022-12-14T14:09:58 | CVE Modified Date | updated | |
2022-12-14 14:15:18 | Received | Awaiting Analysis | Vulnerability Status | updated |
2022-12-15 16:18:17 | Awaiting Analysis | Undergoing Analysis | Vulnerability Status | updated |
2022-12-18 04:35:26 | 2022-12-16T18:25:35 | CVE Modified Date | updated | |
2022-12-18 04:35:26 | Undergoing Analysis | Analyzed | Vulnerability Status | updated |
2022-12-18 04:35:39 | CPE Information | updated |