Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-256m-wxxh-gf6h

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

EPSS

Процентиль: 77%
0.01028
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 7 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
nvd
больше 7 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require the unfiltered_html capability for upload of .js files, which might allow remote attackers to conduct XSS attacks via a crafted file.

CVSS3: 5.4
debian
больше 7 лет назад

wp-includes/functions.php in WordPress before 4.9.1 does not require t ...

EPSS

Процентиль: 77%
0.01028
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79