CVE-2022-2437

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-2437
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-2437.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-2437
Published
2022-07-18T17:15:09Z
Modified
2025-01-08T08:51:07.639603Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

The Feed Them Social – for Twitter feed, Youtube and more plugin for WordPress is vulnerable to deserialization of untrusted input via the 'fts_url' parameter in versions up to, and including 2.9.8.5. This makes it possible for unauthenticated attackers to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.

References

Affected packages

Git / github.com/slickremix/feed-them-social

Affected ranges

Type
GIT
Repo
https://github.com/slickremix/feed-them-social
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.3.7
2.3.8
2.3.9
2.4.0
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
2.5.0
2.5.1
2.5.2
2.5.2.1
2.5.3
2.5.4
2.5.5
2.5.6
2.5.7
2.5.9
2.6.0
2.6.1
2.6.2
2.6.3.1
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.3.1
2.7.4
2.7.5
2.7.6
2.7.6.1
2.7.6.2
2.7.7
2.7.7.1
2.7.7.2
2.7.8
2.7.9
2.8.0
2.8.1
2.8.2
2.8.3.1
2.8.3.2
2.8.3.3
2.8.3.4
2.8.4
2.8.5
2.8.6
2.8.8
2.8.9
2.9.0
2.9.6

v2.*

v2.9.1
v2.9.2
v2.9.3
v2.9.4
v2.9.5
v2.9.6
v2.9.6.1
v2.9.6.2
v2.9.6.3
v2.9.6.4
v2.9.6.5
v2.9.7
v2.9.7.1
v2.9.8
v2.9.8.1.0
v2.9.8.2
v2.9.8.4
v2.9.8.5