[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Remote Code Execution in wordpress -- CVE-2019-9787

ID: oval:org.secpod.oval:def:55473Date: (C)2019-06-19   (M)2022-11-30
Class: VULNERABILITYFamily: unix




WordPress before 5.1.1 does not properly filter comment content, leading to Remote Code Execution by unauthenticated users in a default configuration. This occurs because CSRF protection is mishandled, and because Search Engine Optimization of A elements is performed incorrectly, leading to XSS. The XSS results in administrative access, which allows arbitrary changes to .php files. This is related to wp-admin/includes/ajax-actions.php and wp-includes/comment.php.

Platform:
Debian 9.x
Product:
wordpress
Reference:
CVE-2019-9787
CVE    1
CVE-2019-9787
CPE    119
cpe:/a:wordpress:wordpress:1.0.1
cpe:/a:wordpress:wordpress:1.0.2
cpe:/a:wordpress:wordpress:4.1
cpe:/a:wordpress:wordpress:4.0
...

© SecPod Technologies