CVE-2022-2564

CVSS v3 Score
7.0
High

Vulnerability Description

Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.

CVSS:7.2(High)

admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to c...

CVSS:7.2(High)

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.

CVSS:7.2(High)

SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.

CVSS:7.2(High)

An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm.php, it is possible to send a crafted value in the sel_groups parameter that leads to authenticated ob...

CVSS:7.2(High)

This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.

CVSS:7.2(High)

pathval before version 1.1.1 is vulnerable to prototype pollution.