9.8

CVE-2017-20207

Medienbericht

Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection

Flickr Gallery <= 1.5.2 - Unauthenticated PHP Object Injection

The Flickr Gallery plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.5.2 via deserialization of untrusted input from the `pager ` parameter. This allows unauthenticated attackers to inject a PHP Object. Attackers were actively exploiting this vulnerability with the WP_Theme() class to create backdoors.
Mögliche Gegenmaßnahme
Flickr Gallery: Update to version 1.5.3, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DancoulterFlickr Gallery SwPlatformwordpress Version <= 1.5.2
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Flickr Gallery
Version [*, 1.5.3)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.67% 0.471
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@wordfence.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

https://www.wordfence.com/blog/2017/10/3-zero-day-plugin-vulnerabilities-exploited-wild/
Third Party Advisory
Press/Media Coverage
https://www.wordfence.com/threat-intel/vulnerabilities/id/b52ae51d-7b9a-4047-82bf-723ea87d2375?source=cve
Third Party Advisory
https://plugins.trac.wordpress.org/changeset/1737576/flickr-gallery
Patch
https://www.wordfence.com/threat-intel/vulnerabilities/id/b52ae51d-7b9a-4047-82bf-723ea87d2375
Third Party Advisory