6.5
CVSSv2

CVE-2018-6195

Published: 30/01/2018 Updated: 02/12/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) prior to 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote malicious users to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

splashing images project splashing images

Exploits

WordPress Splashing Images plugin version 21 suffers from PHP object injection and cross site scripting vulnerabilities ...