Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-9061

Опубликовано: 18 мая 2017
Источник: debian
EPSS Низкий

Описание

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressfixed4.7.5+dfsg-1package

Примечания

  • https://wordpress.org/news/2017/05/wordpress-4-7-5/

  • https://github.com/WordPress/WordPress/commit/8c7ea71edbbffca5d9766b7bea7c7f3722ffafa6

EPSS

Процентиль: 82%
0.01766
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 8 лет назад

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

CVSS3: 6.1
nvd
около 8 лет назад

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

CVSS3: 6.1
github
около 3 лет назад

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

EPSS

Процентиль: 82%
0.01766
Низкий