PT-2017-13807 · Debian+1 · Debian+1

Tomdxw

·

Publicado

2017-10-02

·

Atualizado

2019-10-03

·

CVE-2017-14990

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress version 4.8.2 debian linux (affected versions not specified)
Description The issue allows remote attackers to potentially hijack unactivated user accounts by leveraging database read access, such as through an unspecified SQL injection vulnerability. This is because WordPress stores wp signups.activation key values in cleartext, unlike the hashed wp users.user activation key values.
Recommendations For WordPress version 4.8.2, consider updating to a newer version that addresses this issue. For debian linux, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14990
DSA-3997-1

Produtos afetados

Debian
Wordpress