PT-2017-16534 · WordPress · Wordpress

Chris Jean

+1

·

Publicado

2017-01-15

·

Atualizado

2019-10-03

·

CVE-2017-5493

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 4.7.1
Description The issue concerns the Multisite WordPress API, where the wp-includes/ms-functions.php file does not properly generate random numbers for keys. This weakness allows remote attackers to bypass intended access restrictions by crafting specific site signup or user signup requests.
Recommendations For versions prior to 4.7.1, update to version 4.7.1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-5493
DLA-813-1
DSA-3779-1

Produtos afetados

Wordpress