Описание
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-10100
- https://github.com/WordPress/WordPress/commit/14bc2c0a6fde0da04b47130707e01df850eedc7e
- https://codex.wordpress.org/Version_4.9.5
- https://core.trac.wordpress.org/changeset/42892
- https://lists.debian.org/debian-lts-announce/2018/04/msg00031.html
- https://wordpress.org/news/2018/04/wordpress-4-9-5-security-and-maintenance-release
- https://wpvulndb.com/vulnerabilities/9054
- https://www.debian.org/security/2018/dsa-4193
- http://www.securitytracker.com/id/1040836
Связанные уязвимости
CVSS3: 6.1
ubuntu
почти 8 лет назад
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
CVSS3: 6.1
nvd
почти 8 лет назад
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
CVSS3: 6.1
debian
почти 8 лет назад
Before WordPress 4.9.5, the redirection URL for the login page was not ...