CVE-2012-2403
published 2012-04-21CVE-2012-2403: wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.79%
84.8th percentile
wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
Affected
83 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 3.3.2+dfsg-1 (bookworm) | wordpress 3.3.2+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 3.3.1 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-2403: wordpress - wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickabl...
vendor_debian·2012·CVSS 4.3
CVE-2012-2403 [MEDIUM] CVE-2012-2403: wordpress - wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickabl...
wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 3.3.2+dfsg-1)
bullseye: resolved (fixed in 3.3.2+dfsg-1)
forky: resolved (fixed in 3.3.2+dfsg-1)
sid: resolved (fixed in 3.3.2+dfsg-1)
trixie: resolved (fixed in 3.3.2+dfsg-1)
GHSA
GHSA-jqgf-33rj-9cwr: wp-includes/formatting
ghsa_unreviewed·2022-05-17
CVE-2012-2403 [MEDIUM] CWE-79 GHSA-jqgf-33rj-9cwr: wp-includes/formatting
wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
OSV
CVE-2012-2403: wp-includes/formatting
osv·2012-04-21·CVSS 4.3
CVE-2012-2403 [MEDIUM] CVE-2012-2403: wp-includes/formatting
wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
bugzilla·2012-04-23·CVSS 10.0
CVE-2012-2399 [CRITICAL] CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
CVE-2012-2399 CVE-2012-2400 CVE-2012-2402 CVE-2012-2403 CVE-2012-2404 wordpress various flaws [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/
Bugzilla
CVE-2012-2403 wordpress (X < v3.3.2): XSS when making URLs clickable
bugzilla·2012-04-23·CVSS 4.3
CVE-2012-2403 [MEDIUM] CVE-2012-2403 wordpress (X < v3.3.2): XSS when making URLs clickable
CVE-2012-2403 wordpress (X < v3.3.2): XSS when making URLs clickable
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-2403 to the following vulnerability:
wp-includes/formatting.php in WordPress before 3.3.2 attempts to enable clickable links inside attributes, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.
References:
http://core.trac.wordpress.org/changeset/20493/branches/3.3/wp-includes/capabilities.php
http://core.trac.wordpress.org/changeset/20493/branches/3.3/wp-includes/formatting.php
http://wordpress.org/news/2012/04/wordpress-3-3-2/
Discussion:
This issue affects the versions of the wordpress package, as shipped with Fedora release of 15 and 16.
--
This issue affects the versions of the w
http://core.trac.wordpress.org/changeset/20493/branches/3.3/wp-includes/capabilities.phphttp://core.trac.wordpress.org/changeset/20493/branches/3.3/wp-includes/formatting.phphttp://osvdb.org/81463http://secunia.com/advisories/48957http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75093https://exchange.xforce.ibmcloud.com/vulnerabilities/75206http://core.trac.wordpress.org/changeset/20493/branches/3.3/wp-includes/capabilities.phphttp://core.trac.wordpress.org/changeset/20493/branches/3.3/wp-includes/formatting.phphttp://osvdb.org/81463http://secunia.com/advisories/48957http://secunia.com/advisories/49138http://wordpress.org/news/2012/04/wordpress-3-3-2/http://www.debian.org/security/2012/dsa-2470http://www.securityfocus.com/bid/53192https://exchange.xforce.ibmcloud.com/vulnerabilities/75093https://exchange.xforce.ibmcloud.com/vulnerabilities/75206
2012-04-21
Published