Описание
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-10100
- https://github.com/WordPress/WordPress/commit/14bc2c0a6fde0da04b47130707e01df850eedc7e
- https://codex.wordpress.org/Version_4.9.5
- https://core.trac.wordpress.org/changeset/42892
- https://lists.debian.org/debian-lts-announce/2018/04/msg00031.html
- https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release
- https://wpvulndb.com/vulnerabilities/9054
- https://www.debian.org/security/2018/dsa-4193
- http://www.securitytracker.com/id/1040836
Связанные уязвимости
CVSS3: 6.1
ubuntu
больше 7 лет назад
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
CVSS3: 6.1
nvd
больше 7 лет назад
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
CVSS3: 6.1
debian
больше 7 лет назад
Before WordPress 4.9.5, the redirection URL for the login page was not ...