CVE-2017-1001000
WordPress Core < 4.7.2 - Arbitrary Page Modification
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The register_routes function in wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php in the REST API in WordPress 4.7.x before 4.7.2 does not require an integer identifier, which allows remote attackers to modify arbitrary pages via a request for wp-json/wp/v2/posts followed by a numeric value and a non-numeric value, as demonstrated by the wp-json/wp/v2/posts/123?id=123helloworld URI.
La función register_routes en wp-includes/rest-api/endpoints/class-wp-rest-posts-controller.php en la API REST en WordPress 4.7.x en versiones anteriores a 4.7.2 no requiere un identificador de número entero, lo que permite a atacantes remotos modificar páginas arbitrarias a través de una solicitud para wp-json/wp/v2/posts seguida por un valor numérico y un valor no numérico, según lo demostrado mediante la URI wp-json/wp/v2/posts/123?id=123helloworld.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-01-26 CVE Published
- 2017-04-02 CVE Reserved
- 2024-08-05 CVE Updated
- 2024-09-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-285: Improper Authorization
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2017/02/10/16 | Mailing List | |
http://www.securitytracker.com/id/1037731 | Vdb Entry | |
https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html | X_refsource_misc | |
https://blogs.akamai.com/2017/02/wordpress-web-api-vulnerability.html | X_refsource_misc | |
https://codex.wordpress.org/Version_4.7.2 | X_refsource_confirm | |
https://gist.github.com/leonjza/2244eb15510a0687ed93160c623762ab | X_refsource_misc | |
https://github.com/WordPress/WordPress/commit/e357195ce303017d517aff944644a7a1232926f7 | X_refsource_confirm | |
https://make.wordpress.org/core/2017/02/01/disclosure-of-additional-security-fix-in-wordpress-4-7-2 | X_refsource_confirm | |
https://wordpress.org/news/2017/01/wordpress-4-7-2-security-release | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 4.7 Search vendor "Wordpress" for product "Wordpress" and version "4.7" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 4.7.1 Search vendor "Wordpress" for product "Wordpress" and version "4.7.1" | - |
Affected
| ||||||
Wordpress Search vendor "Wordpress" | Wordpress Search vendor "Wordpress" for product "Wordpress" | 4.7.2 Search vendor "Wordpress" for product "Wordpress" and version "4.7.2" | - |
Affected
|