CVE-2016-7168
published 2017-01-05CVE-2016-7168: Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote…
PriorityP421medium4.8CVSS 3.0
AVNACLPRHUIRSCCLILAN
EPSS
2.84%
85.1th percentile
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | wordpress | < wordpress 4.6.1+dfsg-1 (bookworm) | wordpress 4.6.1+dfsg-1 (bookworm) |
| wordpress | wordpress | <= 4.6 | — |
| wordpress | wordpress | >= 0 < 4.6.1+dfsg-1 | 4.6.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.6.1+dfsg-1 | 4.6.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.6.1+dfsg-1 | 4.6.1+dfsg-1 |
| wordpress | wordpress | >= 0 < 4.6.1+dfsg-1 | 4.6.1+dfsg-1 |
CVSS provenance
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
osv4.8MEDIUM
vendor_debian4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ffr7-33wh-7g9r: Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media
ghsa_unreviewed·2022-05-17
CVE-2016-7168 [MEDIUM] CWE-79 GHSA-ffr7-33wh-7g9r: Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
OSV
CVE-2016-7168: Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media
osv·2017-01-05·CVSS 4.8
CVE-2016-7168 [MEDIUM] CVE-2016-7168: Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
Debian
CVE-2016-7168: wordpress - Cross-site scripting (XSS) vulnerability in the media_handle_upload function in ...
vendor_debian·2016·CVSS 4.8
CVE-2016-7168 [MEDIUM] CVE-2016-7168: wordpress - Cross-site scripting (XSS) vulnerability in the media_handle_upload function in ...
Cross-site scripting (XSS) vulnerability in the media_handle_upload function in wp-admin/includes/media.php in WordPress before 4.6.1 might allow remote attackers to inject arbitrary web script or HTML by tricking an administrator into uploading an image file that has a crafted filename.
Scope: local
bookworm: resolved (fixed in 4.6.1+dfsg-1)
bullseye: resolved (fixed in 4.6.1+dfsg-1)
forky: resolved (fixed in 4.6.1+dfsg-1)
sid: resolved (fixed in 4.6.1+dfsg-1)
trixie: resolved (fixed in 4.6.1+dfsg-1)
No detection rules found.
Bugzilla
CVE-2016-7168 CVE-2016-7169 wordpress: two security issues fixed in 4.6.1
bugzilla·2016-09-08·CVSS 4.8
CVE-2016-7168 [MEDIUM] CVE-2016-7168 CVE-2016-7169 wordpress: two security issues fixed in 4.6.1
CVE-2016-7168 CVE-2016-7169 wordpress: two security issues fixed in 4.6.1
Two security issues were fixed in WordPress 4.6.1:
WordPress versions 4.6 and earlier are affected by two security issues: a cross-site scripting vulnerability via image filename, reported by SumOfPwn researcher Cengiz Han Sahin; and a path traversal vulnerability in the upgrade package uploader, reported by Dominik Schilling from the WordPress security team.
External References:
https://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/
Discussion:
Created wordpress tracking bugs for this issue:
Affects: fedora-all [bug 1374480]
Affects: epel-all [bug 1374481]
---
Fixed in:
wordpress-4.6.1-1.el5
wordpress-4.6.1-1.el6
wordpress-4.6.1-1.el7
wordpress-4.6.1-1.fc23
wordpress-4.6.1-1.f
Bugzilla
CVE-2016-7168 CVE-2016-7169 wordpress: two security issues fixed in 4.6.1 [epel-all]
bugzilla·2016-09-08·CVSS 4.8
CVE-2016-7168 [MEDIUM] CVE-2016-7168 CVE-2016-7169 wordpress: two security issues fixed in 4.6.1 [epel-all]
CVE-2016-7168 CVE-2016-7169 wordpress: two security issues fixed in 4.6.1 [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2016-7168 CVE-2016-7169 wordpress: two security issues fixed in 4.6.1 [fedora-all]
bugzilla·2016-09-08·CVSS 4.8
CVE-2016-7168 [MEDIUM] CVE-2016-7168 CVE-2016-7169 wordpress: two security issues fixed in 4.6.1 [fedora-all]
CVE-2016-7168 CVE-2016-7169 wordpress: two security issues fixed in 4.6.1 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
http://www.debian.org/security/2016/dsa-3681http://www.openwall.com/lists/oss-security/2016/09/08/19http://www.openwall.com/lists/oss-security/2016/09/08/24http://www.securityfocus.com/bid/92841https://codex.wordpress.org/Version_4.6.1https://github.com/WordPress/WordPress/commit/c9e60dab176635d4bfaaf431c0ea891e4726d6e0https://sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_vulnerability_in_wordpress_due_to_unsafe_processing_of_file_names.htmlhttps://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/https://wpvulndb.com/vulnerabilities/8615http://www.debian.org/security/2016/dsa-3681http://www.openwall.com/lists/oss-security/2016/09/08/19http://www.openwall.com/lists/oss-security/2016/09/08/24http://www.securityfocus.com/bid/92841https://codex.wordpress.org/Version_4.6.1https://github.com/WordPress/WordPress/commit/c9e60dab176635d4bfaaf431c0ea891e4726d6e0https://sumofpwn.nl/advisory/2016/persistent_cross_site_scripting_vulnerability_in_wordpress_due_to_unsafe_processing_of_file_names.htmlhttps://wordpress.org/news/2016/09/wordpress-4-6-1-security-and-maintenance-release/https://wpvulndb.com/vulnerabilities/8615
2017-01-05
Published