PoC Index

CVE-2022-1753

MEDIUM 5.4EPSS 0.9%

A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. It is possible to launch the attack remotely but it might require authentication. A video explaining the attack has been disclosed to the public.

CVSS v3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS v2.0
4.0 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
EPSS
0.92% chance of exploitation in the next 30 days, 58th percentile
Published
2022-05-17
Updated
2025-04-15

Proof-of-concept exploits (2)

References

Related