Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5776

Опубликовано: 18 янв. 2018
Источник: debian
EPSS Низкий

Описание

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
wordpressfixed4.9.2+dfsg-1package
wordpressnot-affectedstretchpackage
wordpressnot-affectedjessiepackage
wordpressnot-affectedwheezypackage

Примечания

  • For jessie and stretch version the files silverlightmediaelement.xap and

  • flashmediaelement.swf have been removed with the 4.1+dfsg-1 version.

  • sid in version 4.9.1+dfsg-1 did as well *not* have the files but track here the

  • final wordpress version 4.9.2 which finally removed the mediaelement files.

  • https://wordpress.org/news/2018/01/wordpress-4-9-2-security-and-maintenance-release/

  • https://github.com/WordPress/WordPress/commit/3fe9cb61ee71fcfadb5e002399296fcc1198d850

EPSS

Процентиль: 84%
0.0242
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 7 лет назад

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVSS3: 6.1
nvd
больше 7 лет назад

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

CVSS3: 6.1
github
около 3 лет назад

WordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).

EPSS

Процентиль: 84%
0.0242
Низкий