CVE-2022-1392
Videos sync PDF <= 1.7.4 - Unauthenticated LFI
Record summary
CVE-2022-1392 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The Videos sync PDF WordPress plugin through 1.7.4 does not validate the p parameter before using it in an include statement, which could lead to Local File Inclusion issues
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Videos sync PDF | CVE List | 1.7.4 to ≤ 1.7.4 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Videos sync PDF <=1.7.4 - Local File InclusionCVSS 7.5
WordPress Videos sync PDF 1.7.4 and prior does not validate the p parameter before using it in an include statement, which could lead to local file inclusion.
Impact
Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, potentially leading to further compromise of the system.
Remediation
Upgrade to the latest version of WordPress Videos sync PDF plugin (>=1.7.5) or apply the vendor-provided patch to mitigate the vulnerability.
Source: ProjectDiscovery