← Zuruck zu CVEs
CVE-2019-17675
HIGH8.8
Beschreibung
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVE Details
CVSS v3.1 Bewertung8.8
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionREQUIRED
Veroffentlicht10/17/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
debian:debian_linuxwordpress:wordpress
Schwachen (CWE)
CWE-352CWE-843
Referenzen
https://blog.wpscan.org/wordpress/security/release/2019/10/15/wordpress-524-security-release-breakdown.html(cve@mitre.org)
https://core.trac.wordpress.org/changeset/46477(cve@mitre.org)
https://github.com/WordPress/WordPress/commit/b183fd1cca0b44a92f0264823dd9f22d2fd8b8d0(cve@mitre.org)
https://seclists.org/bugtraq/2020/Jan/8(cve@mitre.org)
https://wpvulndb.com/vulnerabilities/9913(cve@mitre.org)
https://www.debian.org/security/2020/dsa-4599(cve@mitre.org)
https://www.debian.org/security/2020/dsa-4677(cve@mitre.org)
https://blog.wpscan.org/wordpress/security/release/2019/10/15/wordpress-524-security-release-breakdown.html(af854a3a-2127-422b-91ae-364da2661108)
https://core.trac.wordpress.org/changeset/46477(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/WordPress/WordPress/commit/b183fd1cca0b44a92f0264823dd9f22d2fd8b8d0(af854a3a-2127-422b-91ae-364da2661108)
https://lists.debian.org/debian-lts-announce/2019/11/msg00000.html(af854a3a-2127-422b-91ae-364da2661108)
https://seclists.org/bugtraq/2020/Jan/8(af854a3a-2127-422b-91ae-364da2661108)
https://wordpress.org/news/2019/10/wordpress-5-2-4-security-release/(af854a3a-2127-422b-91ae-364da2661108)
https://wpvulndb.com/vulnerabilities/9913(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2020/dsa-4599(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2020/dsa-4677(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.