PT-2019-5221 · WordPress · Wordpress

Evan Ricafort

·

Publicado

2019-09-11

·

Atualizado

2023-02-04

·

CVE-2019-17675

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WordPress versions prior to 5.2.4
Description The issue is related to a type confusion error during referer validation on admin pages, which could lead to a CSRF attack. This might allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For versions prior to 5.2.4, update to version 5.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to admin pages to minimize the risk of exploitation.

Correção

CSRF

Type Confusion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-01950
CVE-2019-17675
DLA-1980-1
DSA-4599-1
DSA-4677-1

Produtos afetados

Wordpress