Lucene search

K
osvGoogleOSV:CVE-2017-17091
HistoryDec 02, 2017 - 6:29 a.m.

CVE-2017-17091

2017-12-0206:29:00
Google
osv.dev
4

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

72.8%

wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

72.8%