A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Feb/95 | Exploit Mailing List Third Party Advisory |
https://vuldb.com/?id.97383 | Third Party Advisory VDB Entry |
Configurations
History
29 Jun 2022, 17:59
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.0
v3 : 7.5 |
CWE | CWE-94 | |
CPE | cpe:2.3:a:automattic:vaultpress:1.8.4:*:*:*:*:wordpress:*:* | |
References | (N/A) http://seclists.org/fulldisclosure/2017/Feb/95 - Exploit, Mailing List, Third Party Advisory | |
References | (N/A) https://vuldb.com/?id.97383 - Third Party Advisory, VDB Entry |
23 Jun 2022, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-06-23 05:15
Updated : 2024-02-04 22:29
NVD link : CVE-2017-20086
Mitre link : CVE-2017-20086
CVE.ORG link : CVE-2017-20086
JSON object : View
Products Affected
automattic
- vaultpress
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')