TROYANOSYVIRUS
Volver a CVEs

CVE-2019-17675

HIGH
8.8

Descripcion

WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.

Detalles CVE

Puntuacion CVSS v3.18.8
SeveridadHIGH
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado10/17/2019
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

debian:debian_linuxwordpress:wordpress

Debilidades (CWE)

CWE-352CWE-843

Referencias

https://core.trac.wordpress.org/changeset/46477(af854a3a-2127-422b-91ae-364da2661108)
https://seclists.org/bugtraq/2020/Jan/8(af854a3a-2127-422b-91ae-364da2661108)
https://wpvulndb.com/vulnerabilities/9913(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2020/dsa-4599(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2020/dsa-4677(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.