CVE-2020-35938
Team Showcase <= 1.22.15 - Object Injection
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
PHP Object injection vulnerabilities in the Post Grid plugin before 2.0.73 for WordPress allow remote authenticated attackers to inject arbitrary PHP objects due to insecure unserialization of data supplied in a remotely hosted crafted payload in the source parameter via AJAX. The action must be set to post_grid_import_xml_layouts.
Unas vulnerabilidades de inyección de objetos PHP en el plugin Post Grid versiones anteriores a 2.0.73 para WordPress, permiten a atacantes autenticados remotos inyectar objetos PHP arbitrarios debido a una deserialización no segura de los datos suministrados en una carga útil diseñada hosteada remotamente en el parámetro source por medio de AJAX. La acción debe ser establecida en la función post_grid_import_xml_layouts.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-09-17 CVE Published
- 2021-01-01 CVE Reserved
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.wordfence.com/blog/2020/10/high-severity-vulnerabilities-in-post-grid-and-team-showcase-plugins | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pickplugins Search vendor "Pickplugins" | Post Grid Search vendor "Pickplugins" for product "Post Grid" | < 2.0.73 Search vendor "Pickplugins" for product "Post Grid" and version " < 2.0.73" | wordpress |
Affected
| ||||||
Pickplugins Search vendor "Pickplugins" | Team Showcase Search vendor "Pickplugins" for product "Team Showcase" | < 1.22.16 Search vendor "Pickplugins" for product "Team Showcase" and version " < 1.22.16" | wordpress |
Affected
|