Vulnerability Name: | CVE-2013-5739 (CCN-87145) | ||||||||||||||||||||||||
Assigned: | 2013-09-11 | ||||||||||||||||||||||||
Published: | 2013-09-11 | ||||||||||||||||||||||||
Updated: | 2013-09-27 | ||||||||||||||||||||||||
Summary: | The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php. | ||||||||||||||||||||||||
CVSS v3 Severity: | 4.6 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N) 2.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N/E:U/RL:OF/RC:C)
4.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||
References: | Source: CONFIRM Type: Vendor Advisory http://codex.wordpress.org/Version_3.6.1 Source: CCN Type: WordPress Trac Repository Web Site WordPress Trac Repository Source: CONFIRM Type: Exploit, Patch http://core.trac.wordpress.org/changeset/25322 Source: MITRE Type: CNA CVE-2013-5739 Source: CCN Type: SA54803 WordPress Multiple Vulnerabilities Source: CCN Type: WordPress Web site WordPress 3.6.1 Maintenance and Security Release Source: CONFIRM Type: Patch, Vendor Advisory http://wordpress.org/news/2013/09/wordpress-3-6-1/ Source: DEBIAN Type: UNKNOWN DSA-2757 Source: CCN Type: BID-62421 WordPress 'get_allowed_mime_types()' Function CVE-2013-5739 Remote Security Weakness Source: XF Type: UNKNOWN wordpress-cve20135739-file-upload(87145) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-5739 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |