Vulnerabilities > CVE-2022-1409 - Unspecified vulnerability in Vikwp Hotel Booking Engine & PMS

047910
CVSS 7.2 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
vikwp

Summary

The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.5.8 does not properly validate images, allowing high privilege users such as administrators to upload PHP files disguised as images and containing malicious PHP code

Vulnerable Configurations

Part Description Count
Application
Vikwp
1