Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6514

Опубликовано: 22 мая 2019
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wordpress:wordpress:4.7.2:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01457
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 6 лет назад

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS3: 5.3
debian
около 6 лет назад

WordPress 4.7.2 mishandles listings of post authors, which allows remo ...

github
около 3 лет назад

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

EPSS

Процентиль: 80%
0.01457
Низкий

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
Уязвимость CVE-2017-6514