| Vulnerability Name: | CVE-2016-2221 (CCN-110787) | ||||||||||||||||||||||||||||||||||||||||||||
| Assigned: | 2016-02-02 | ||||||||||||||||||||||||||||||||||||||||||||
| Published: | 2016-02-02 | ||||||||||||||||||||||||||||||||||||||||||||
| Updated: | 2017-11-04 | ||||||||||||||||||||||||||||||||||||||||||||
| Summary: | Open redirect vulnerability in the wp_validate_redirect function in wp-includes/pluggable.php in WordPress before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL that triggers incorrect hostname parsing, as demonstrated by an https:example.com URL. CWE-601: URL Redirection to Untrusted Site ('Open Redirect') | ||||||||||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 7.4 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N) 6.4 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N/E:U/RL:O/RC:C)
7.7 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
| ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-2221 Source: CCN Type: oss-sec Mailing List, Thu, 4 Feb 2016 16:16:31 -0500 (EST) Re: CVE Request: WordPress: New 4.4.2 security and maintenance release: SSRF and open redirect vulnerability Source: CCN Type: SECTRACK ID: 1034933 WordPress Bugs Let Remote Users Conduct Server-Side Request Forgery and Open Redirect Attacks Source: DEBIAN Type: UNKNOWN DSA-3472 Source: BID Type: UNKNOWN 82463 Source: CCN Type: BID-82463 WordPress Prior to 4.4.2 Open Redirection Vulnerability Source: SECTRACK Type: UNKNOWN 1034933 Source: CONFIRM Type: Patch https://codex.wordpress.org/Version_4.4.2 Source: CONFIRM Type: Patch https://core.trac.wordpress.org/changeset/36444 Source: XF Type: UNKNOWN wordpress-cve20162221-xsrf(110787) Source: CCN Type: WordPress Web site WordPress 4.4.2 Security and Maintenance Release Source: CONFIRM Type: Patch, Vendor Advisory https://wordpress.org/news/2016/02/wordpress-4-4-2-security-and-maintenance-release/ Source: MISC Type: UNKNOWN https://wpvulndb.com/vulnerabilities/8377 Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-2221 | ||||||||||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||||||||||