Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3gc-45gm-v55m

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

EPSS

Процентиль: 81%
0.01668
Низкий

7.5 High

CVSS3

Дефекты

CWE-338

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
nvd
больше 8 лет назад

wp-includes/ms-functions.php in the Multisite WordPress API in WordPress before 4.7.1 does not properly choose random numbers for keys, which makes it easier for remote attackers to bypass intended access restrictions via a crafted (1) site signup or (2) user signup.

CVSS3: 7.5
debian
больше 8 лет назад

wp-includes/ms-functions.php in the Multisite WordPress API in WordPre ...

EPSS

Процентиль: 81%
0.01668
Низкий

7.5 High

CVSS3

Дефекты

CWE-338