Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j2rp-vprg-5m9q

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

EPSS

Процентиль: 66%
0.00529
Низкий

8.6 High

CVSS3

Дефекты

CWE-285
CWE-918

Связанные уязвимости

CVSS3: 8.6
ubuntu
почти 9 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
nvd
почти 9 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP address formats when determining an intranet address, which allows remote attackers to bypass an intended SSRF protection mechanism via a crafted address.

CVSS3: 8.6
debian
почти 9 лет назад

WordPress before 4.5 does not consider octal and hexadecimal IP addres ...

EPSS

Процентиль: 66%
0.00529
Низкий

8.6 High

CVSS3

Дефекты

CWE-285
CWE-918