PT-2017-14248 · WordPress · User-Login-History

Publicado

2017-10-24

·

Atualizado

2017-11-14

·

CVE-2017-15867

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions user-login-history plugin for WordPress versions through 1.5.2
Description The issue allows remote attackers to inject arbitrary web script or HTML via several parameters to the "admin/partials/listing/listing.php" endpoint, including date from, date to, user id, username, country name, browser, operating system, or ip address.
Recommendations For user-login-history plugin for WordPress versions through 1.5.2, consider disabling access to the "admin/partials/listing/listing.php" endpoint until a patch is available. Restrict the use of the vulnerable parameters date from, date to, user id, username, country name, browser, operating system, and ip address to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15867

Produtos afetados

User-Login-History