Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xfxw-2xqv-g5xx

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

EPSS

Процентиль: 71%
0.00715
Низкий

Дефекты

CWE-20

Связанные уязвимости

ubuntu
почти 12 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

nvd
почти 12 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

debian
почти 12 лет назад

The get_allowed_mime_types function in wp-includes/functions.php in Wo ...

EPSS

Процентиль: 71%
0.00715
Низкий

Дефекты

CWE-20