A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.
References
Link | Resource |
---|---|
http://seclists.org/fulldisclosure/2017/Feb/95 | Exploit Mailing List Third Party Advisory |
https://vuldb.com/?id.97383 | Third Party Advisory VDB Entry |
http://seclists.org/fulldisclosure/2017/Feb/95 | Exploit Mailing List Third Party Advisory |
https://vuldb.com/?id.97383 | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 03:22
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 6.0
v3 : 6.3 |
References | () http://seclists.org/fulldisclosure/2017/Feb/95 - Exploit, Mailing List, Third Party Advisory | |
References | () https://vuldb.com/?id.97383 - Third Party Advisory, VDB Entry |
Information
Published : 2022-06-23 05:15
Updated : 2024-11-21 03:22
NVD link : CVE-2017-20086
Mitre link : CVE-2017-20086
CVE.ORG link : CVE-2017-20086
JSON object : View
Products Affected
automattic
- vaultpress
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')