Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9061

Опубликовано: 18 мая 2017
Источник: debian
EPSS Низкий

Описание

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressfixed4.7.5+dfsg-1package

Примечания

  • https://wordpress.org/news/2017/05/wordpress-4-7-5/

  • https://github.com/WordPress/WordPress/commit/8c7ea71edbbffca5d9766b7bea7c7f3722ffafa6

EPSS

Процентиль: 87%
0.03308
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 8 лет назад

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

CVSS3: 6.1
nvd
больше 8 лет назад

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

CVSS3: 6.1
github
больше 3 лет назад

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

EPSS

Процентиль: 87%
0.03308
Низкий