Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v4p8-jvp4-22m6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-79

Связанные уязвимости

ubuntu
почти 12 лет назад

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

nvd
почти 12 лет назад

The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

debian
почти 12 лет назад

The default configuration of WordPress before 3.6.1 does not prevent u ...

EPSS

Процентиль: 52%
0.00295
Низкий

Дефекты

CWE-79