CVE-2022-4171 MEDIUM

CVE-2022-4171: demon image annotation <= 5.0 - Improper Input Restriction Validation

Vendor Demonisblack
Product demon image annotation
Weakness CWE-1284
Published December 13, 2022
Last update April 8, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

The demon image annotation plugin for WordPress is vulnerable to improper input validation in versions up to, and including 5.0. This is due to the plugin improperly validating the number of characters supplied during an annotation despite there being a setting to limit the number characters input. This means that unauthenticated attackers can bypass the length restrictions and input more characters than allowed via the settings.

Explanation of Vulnerability in Simple Terms

02Summary

Demon Image Annotation versions 5.0 and earlier contain a vulnerability that allows an attacker to modify data or disrupt service without authentication. The flaw stems from insufficient input validation or access controls. No confidentiality impact is present, but integrity and availability of the annotation system can be compromised. Update to a version newer than 5.0 when available.

What an attacker can do

03Attacker Capabilities

Modify annotation data or cause the service to become unavailable without needing to log in.

Potential impact on your site

04Site Impact

Attackers can corrupt image annotations or disrupt the annotation service for all users.

Conditions required to exploit

05Prerequisites

Network access to the application; no authentication or user interaction required.

Key dates

06Disclosure timeline

December 13, 2022 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE