CVE-2017-6514 Information
Feb 14, 2021
cve
Description
WordPress 4.7.2 mishandles listings of post authors which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request related to the \author_name:\ substring.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
http://www.securityfocus.com/bid/108459
https://github.com/CFSECURITE/wordpress
https://web.archive.org/web/20180612235401/https://github.com/CFSECURITE/wordpress
WordPress
4.7.2
mishandles
listings
of
post
authors
which
allows
remote
attackers
to
obtain
sensitive
information
(Path
Disclosure)
via
a
/wp-json/oembed/1.0/embed?url=
request
related
to
the
\author_name:
substring.
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: