Lucene search

K
cve[email protected]CVE-2015-3438
HistoryAug 05, 2015 - 1:59 a.m.

CVE-2015-3438

2015-08-0501:59:00
CWE-79
web.nvd.nist.gov
47
cve-2015-3438
cross-site scripting
xss
wordpress
security
vulnerability
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.028

Percentile

90.6%

Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 4.1.2, when MySQL is used without strict mode, allow remote attackers to inject arbitrary web script or HTML via a (1) four-byte UTF-8 character or (2) invalid character that reaches the database layer, as demonstrated by a crafted character in a comment.

Affected configurations

NVD
Node
wordpresswordpressRange4.1.1
Node
debiandebian_linuxMatch7.0
OR
debiandebian_linuxMatch8.0
CPENameOperatorVersion
wordpress:wordpresswordpressle4.1.1

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.4

Confidence

High

EPSS

0.028

Percentile

90.6%