CVE-2022-2437
Feed Them Social – for Twitter feed, Youtube and more <= 2.9.8.5 - Unauthenticated PHAR Deserialization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
El plugin Feed Them Social - for Twitter feed, Youtube and more para WordPress es vulnerable a una deserialización de entradas no confiables por medio del parámetro "fts_url" en versiones hasta la 2.9.8.5 incluyéndola. Esto hace posible que atacantes no autenticados llamen a los archivos usando un envoltorio PHAR que de serializará los datos y llamará a objetos PHP arbitrarios que pueden ser usados para llevar a cabo una variedad de acciones maliciosas concedidas una cadena POP también está presente. También requiere que el atacante tenga éxito en cargar un archivo con la carga útil serializada
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-12 CVE Published
- 2022-07-15 CVE Reserved
- 2024-08-03 CVE Updated
- 2024-09-24 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/threat-intel/vulnerabilities/id/50bcea94-b12a-4b31-b0c1-bba834ea9bd0?source=cve | Third Party Advisory | |
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-2437 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Slickremix Search vendor "Slickremix" | Feed Them Social Search vendor "Slickremix" for product "Feed Them Social" | < 2.9.8.6 Search vendor "Slickremix" for product "Feed Them Social" and version " < 2.9.8.6" | wordpress |
Affected
|