Lucene search

K
cve[email protected]CVE-2013-5738
HistorySep 12, 2013 - 1:30 p.m.

CVE-2013-5738

2013-09-1213:30:13
CWE-20
web.nvd.nist.gov
37
wordpress
get_allowed_mime_types
functions.php
xss
cve-2013-5738
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.1

Confidence

High

EPSS

0.002

Percentile

61.9%

The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

Affected configurations

NVD
Node
wordpresswordpressRange≀3.6
VendorProductVersionCPE
wordpresswordpresscpe:/a:wordpress:wordpress::::

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.1

Confidence

High

EPSS

0.002

Percentile

61.9%