Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-4422
HistorySep 14, 2012 - 12:00 a.m.

CVE-2012-4422

2012-09-1400:00:00
ubuntu.com
ubuntu.com
10

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

52.4%

wp-admin/plugins.php in WordPress before 3.4.2, when the multisite feature
is enabled, does not check for network-administrator privileges before
performing a network-wide activation of an installed plugin, which might
allow remote authenticated users to make unintended plugin changes by
leveraging the Administrator role.

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:N/I:P/A:N

EPSS

0.002

Percentile

52.4%