CVE-2017-6514Sensitive Information Exposure in Wordpress

Severity
5.3MEDIUMNVD
EPSS
1.4%
top 19.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 22
Latest updateMay 24

Description

WordPress 4.7.2 mishandles listings of post authors, which allows remote attackers to obtain sensitive information (Path Disclosure) via a /wp-json/oembed/1.0/embed?url= request, related to the "author_name":" substring.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-rc6p-mq83-6q2w: WordPress 42022-05-24
OSV
CVE-2017-6514: WordPress 42019-05-22

📋Vendor Advisories

1
Debian
CVE-2017-6514: wordpress - WordPress 4.7.2 mishandles listings of post authors, which allows remote attacke...2017