CVE-2014-5240
published 2014-08-18CVE-2014-5240: Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated…
PriorityP412low2.1CVSS 2.0
AVNACHAuSCNIPAN
EPSS
2.20%
80.6th percentile
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
Affected
38 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | wordpress | < wordpress 3.9.2+dfsg-1 (bookworm) | wordpress 3.9.2+dfsg-1 (bookworm) |
| openstack | neutron | >= 0 < 7.0.0 | 7.0.0 |
| wordpress | wordpress | <= 3.9.1 | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
| wordpress | wordpress | — | — |
CVSS provenance
nvdv2.02.1LOWAV:N/AC:H/Au:S/C:N/I:P/A:N
osv2.1LOW
vendor_redhat3.5LOW
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-324x-63mr-8cqc: Cross-site scripting (XSS) vulnerability in wp-includes/pluggable
ghsa_unreviewed·2022-05-17
CVE-2014-5240 [LOW] CWE-79 GHSA-324x-63mr-8cqc: Cross-site scripting (XSS) vulnerability in wp-includes/pluggable
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
GHSA
OpenStack Neutron Race condition vulnerability
ghsa·2022-05-17
CVE-2015-5240 [LOW] CWE-362 OpenStack Neutron Race condition vulnerability
OpenStack Neutron Race condition vulnerability
Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.
OSV
CVE-2014-5240: Cross-site scripting (XSS) vulnerability in wp-includes/pluggable
osv·2014-08-18·CVSS 2.1
CVE-2014-5240 [LOW] CVE-2014-5240: Cross-site scripting (XSS) vulnerability in wp-includes/pluggable
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
Red Hat
openstack-neutron: Firewall rules bypass through port update
vendor_redhat·2015-09-08·CVSS 3.5
CVE-2015-5240 [LOW] CWE-362 openstack-neutron: Firewall rules bypass through port update
openstack-neutron: Firewall rules bypass through port update
Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.
A race-condition flaw leading to ACL bypass was discovered in OpenStack Networking (neutron). An authenticated user could change the owner of a port after it was created but before firewall rules were applied, thus preventing firewall control checks from occurring. All OpenStack Networking deployments that used either the ML2 plug-in or a plug-in that relied on the security groups AMQP API were affected.
Debian
CVE-2014-5240: wordpress - Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPre...
vendor_debian·2014·CVSS 2.1
CVE-2014-5240 [LOW] CVE-2014-5240: wordpress - Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPre...
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote authenticated administrators to inject arbitrary web script or HTML, and obtain Super Admin privileges, via a crafted avatar URL.
Scope: local
bookworm: resolved (fixed in 3.9.2+dfsg-1)
bullseye: resolved (fixed in 3.9.2+dfsg-1)
forky: resolved (fixed in 3.9.2+dfsg-1)
sid: resolved (fixed in 3.9.2+dfsg-1)
trixie: resolved (fixed in 3.9.2+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5240 openstack-neutron: Firewall rules bypass through port update
bugzilla·2015-08-31·CVSS 3.5
CVE-2015-5240 [LOW] CVE-2015-5240 openstack-neutron: Firewall rules bypass through port update
CVE-2015-5240 openstack-neutron: Firewall rules bypass through port update
It was reported that a vulnerability was found in Neutron. By changing the device owner of an instance's port right after it is created, an authenticated user may prevent application of firewall rules and so avoid IP anti-spoofing controls. All Neutron setups using the ML2 plugin or a plugin that relies on the security groups AMQP API are affected. All Neutron setups using the ML2 plugin or a plugin that relies on the security groups AMQP API are affected.
Vulnerability affects versions through 2014.2.3 and 2015.1 versions through 2015.1.1
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Kevin Benton from Mirantis as the original reporter.
Disc
Bugzilla
CVE-2014-5203 CVE-2014-5204 CVE-2014-5205 CVE-2014-5240 wordpress: multiple vulnerabilities fixed upstream
bugzilla·2014-08-13·CVSS 7.5
CVE-2014-5203 [HIGH] CVE-2014-5203 CVE-2014-5204 CVE-2014-5205 CVE-2014-5240 wordpress: multiple vulnerabilities fixed upstream
CVE-2014-5203 CVE-2014-5204 CVE-2014-5205 CVE-2014-5240 wordpress: multiple vulnerabilities fixed upstream
CVE-2014-5203: an unsafe serialization vulnerability.
Affected versions 3.9 and 3.9.1.
Commit with a fix: https://core.trac.wordpress.org/changeset/29389
CVE-2014-5204: protections against brute attacks against CSRF tokens.
Affected WordPress versions 2.0.3 - 3.9.1 (except 3.7.4 / 3.8.4)
Commit: https://core.trac.wordpress.org/changeset/29384
CVE-2014-5205: https://core.trac.wordpress.org/changeset/29408
Discussion:
Created wordpress tracking bugs for this issue:
Affects: fedora-all [bug 1129751]
Affects: epel-all [bug 1129752]
---
MITRE assigned CVE-2014-5240 to the https://core.trac.wordpress.org/changeset/29398 XSS issue:
http://seclists.org/oss-sec/2014/q3/364
---
wordp
http://openwall.com/lists/oss-security/2014/08/13/3http://www.debian.org/security/2014/dsa-3001https://core.trac.wordpress.org/changeset/29398https://wordpress.org/news/2014/08/wordpress-3-9-2/http://openwall.com/lists/oss-security/2014/08/13/3http://www.debian.org/security/2014/dsa-3001https://core.trac.wordpress.org/changeset/29398https://wordpress.org/news/2014/08/wordpress-3-9-2/
2014-08-18
Published