Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-4421
HistorySep 14, 2012 - 12:00 a.m.

CVE-2012-4421

2012-09-1400:00:00
ubuntu.com
ubuntu.com
10

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

56.0%

The create_post function in wp-includes/class-wp-atom-server.php in
WordPress before 3.4.2 does not perform a capability check, which allows
remote authenticated users to bypass intended access restrictions and
publish new posts by leveraging the Contributor role and using the Atom
Publishing Protocol (aka AtomPub) feature.

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

56.0%