Vulnerability Name: | CVE-2015-7989 (CCN-107848) | ||||||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2015-10-26 | ||||||||||||||||||||||||||||||||||||||||||||||||
Published: | 2015-10-26 | ||||||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2017-11-04 | ||||||||||||||||||||||||||||||||||||||||||||||||
Summary: | Cross-site scripting (XSS) vulnerability in the user list table in WordPress before 4.3.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted e-mail address, a different vulnerability than CVE-2015-5714. | ||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 4.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C)
5.3 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
| ||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-79 | ||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Cross-Site Scripting | ||||||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-7989 Source: CCN Type: oss-sec Mailing List, Mon, 26 Oct 2015 20:32:44 +0100 CVE Request: Wordpress: Cross-site scripting vulnerability in the user list table Source: CCN Type: oss-sec Mailing List, Wed, 28 Oct 2015 00:55:17 -0400 (EDT) Re: CVE Request: Wordpress: Cross-site scripting vulnerability in the user list table Source: CCN Type: SECTRACK ID: 1033979 WordPress Bugs Let Remote Users Conduct Cross-Site Scripting Attacks and Bypass Publishing Permission Checks Source: DEBIAN Type: UNKNOWN DSA-3375 Source: DEBIAN Type: UNKNOWN DSA-3383 Source: SECTRACK Type: UNKNOWN 1033979 Source: CONFIRM Type: Patch, Vendor Advisory https://codex.wordpress.org/Version_4.3.1 Source: XF Type: UNKNOWN wordpress-cve20157989-xss(107848) Source: CONFIRM Type: Patch https://github.com/WordPress/WordPress/commit/f91a5fd10ea7245e5b41e288624819a37adf290a Source: CONFIRM Type: UNKNOWN https://security-tracker.debian.org/tracker/CVE-2015-7989 Source: CCN Type: WordPress Web Site WordPress 4.3.1 Security and Maintenance Release Source: CONFIRM Type: Patch, Vendor Advisory https://wordpress.org/news/2015/09/wordpress-4-3-1/ Source: MISC Type: UNKNOWN https://wpvulndb.com/vulnerabilities/8187 Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-7989 | ||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||
BACK |