CVE-2014-125110
wp-file-upload Plugin wfu_ajaxactions.php wfu_ajax_action_callback cross site scripting
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback of the file lib/wfu_ajaxactions.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 2.4.4 is able to address this issue. The identifier of the patch is c846327df030a0a97da036a2f07c769ab9284ddb. It is recommended to upgrade the affected component. The identifier VDB-258781 was assigned to this vulnerability.
Se encontró una vulnerabilidad en el complemento wp-file-upload de WordPress hasta 2.4.3 y se clasificó como problemática. La función wfu_ajax_action_callback del archivo lib/wfu_ajaxactions.php es afectada por esta vulnerabilidad. La manipulación conduce a cross-site scripting. El ataque se puede lanzar de forma remota. La actualización a la versión 2.4.4 puede solucionar este problema. El identificador del parche es c846327df030a0a97da036a2f07c769ab9284ddb. Se recomienda actualizar el componente afectado. A esta vulnerabilidad se le asignó el identificador VDB-258781.
In wp-file-upload Plugin bis 2.4.3 für WordPress wurde eine Schwachstelle gefunden. Sie wurde als problematisch eingestuft. Das betrifft die Funktion wfu_ajax_action_callback der Datei lib/wfu_ajaxactions.php. Mittels Manipulieren mit unbekannten Daten kann eine cross site scripting-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk angegangen werden. Ein Aktualisieren auf die Version 2.4.4 vermag dieses Problem zu lösen. Der Patch wird als c846327df030a0a97da036a2f07c769ab9284ddb bezeichnet. Als bestmögliche Massnahme wird das Einspielen eines Upgrades empfohlen.
The WordPress File Upload plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 2.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2014-08-20 CVE Published
- 2024-03-30 CVE Reserved
- 2024-04-01 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://vuldb.com/?id.258781 | Technical Description |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/wp-plugins/wp-file-upload/commit/c846327df030a0a97da036a2f07c769ab9284ddb | 2024-05-17 | |
https://github.com/wp-plugins/wp-file-upload/releases/tag/2.4.4 | 2024-05-17 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wp File Upload Search vendor "Wp File Upload" | Wp File Upload Search vendor "Wp File Upload" for product "Wp File Upload" | >= 0.0.0 <= 2.4.3 Search vendor "Wp File Upload" for product "Wp File Upload" and version " >= 0.0.0 <= 2.4.3" | en |
Affected
|