NA

CVE-2022-4063

Published: 19/12/2022 Updated: 07/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The InPost Gallery WordPress plugin prior to 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing malicious users to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pluginus inpost gallery

Github Repositories

Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE

INPGer | CVE-2022-4063 - InPost Gallery Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery &lt; 2141 - Unauthenticated LFI to RCEUsing GNU Parallel You must have parallel for running this tool If you found error like "$'\r': command not found" just do "dos2unix inpgersh" Install Parallel Linux : apt-get in