Lucene search

K
cveRedhatCVE-2012-3383
HistoryJul 22, 2012 - 5:55 p.m.

CVE-2012-3383

2012-07-2217:55:03
CWE-264
redhat
web.nvd.nist.gov
39
cve-2012-3383
wordpress
xss
remote authentication
nvd

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.003

Percentile

70.8%

The map_meta_cap function in wp-includes/capabilities.php in WordPress 3.4.x before 3.4.2, when the multisite feature is enabled, does not properly assign the unfiltered_html capability, which allows remote authenticated users to bypass intended access restrictions and conduct cross-site scripting (XSS) attacks by leveraging the Administrator or Editor role and composing crafted text.

Affected configurations

Nvd
Node
wordpresswordpressMatch3.4.0
VendorProductVersionCPE
wordpresswordpress3.4.0cpe:2.3:a:wordpress:wordpress:3.4.0:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.003

Percentile

70.8%