8.8
CVE-2018-1000773
- EPSS 23.95%
- Veröffentlicht 06.09.2018 16:29:05
- Zuletzt bearbeitet 21.11.2024 03:40:22
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
WordPress Core < 5.0.1 - PHAR Unserialization
WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time.
Mögliche Gegenmaßnahme
WordPress: Update to one of the following versions, or a newer patched version: 3.7.28, 3.8.28, 3.9.26, 4.0.25, 4.1.25, 4.2.22, 4.3.18, 4.4.17, 4.5.16, 4.6.13, 4.7.12, 4.8.8, 4.9.9, 5.0.1
Weitere Schwachstelleninformationen
SystemWordPress Core
≫
Produkt
WordPress
Version
[*, 3.7)
Version
3.7 - 3.7.27
Version
3.8 - 3.8.27
Version
3.9 - 3.9.25
Version
4.0 - 4.0.24
Version
4.1 - 4.1.24
Version
4.2 - 4.2.21
Version
4.3 - 4.3.17
Version
4.4 - 4.4.16
Version
4.5 - 4.5.15
Version
4.6 - 4.6.12
Version
4.7 - 4.7.11
Version
4.8 - 4.8.7
Version
4.9 - 4.9.8
Version
5.0
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 23.95% | 0.958 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.