CVE-2017-17091
02.12.2017, 06:29
wp-admin/user-new.php in WordPress before 4.9.1 sets the newbloguser key to a string that can be directly derived from the user ID, which allows remote attackers to bypass intended access restrictions by entering this string.Enginsight
| Vendor | Product | Version |
|---|---|---|
| wordpress | wordpress | 𝑥 ≤ 4.9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| wordpress |
|
Common Weakness Enumeration
References