CVE-2017-9066Server-Side Request Forgery in Wordpress

Severity
8.6HIGHNVD
EPSS
1.4%
top 19.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 18
Latest updateMay 14

Description

In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP class, leading to SSRF.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:NExploitability: 3.9 | Impact: 4.0

Affected Packages3 packages

debiandebian/wordpress< wordpress 4.7.5+dfsg-1 (bookworm)
Debianwordpress/wordpress< 4.7.5+dfsg-1+3

Also affects: Debian Linux 8.0, 9.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hmqr-j9c3-8h75: In WordPress before 42022-05-14
OSV
CVE-2017-9066: In WordPress before 42017-05-18

📋Vendor Advisories

1
Debian
CVE-2017-9066: wordpress - In WordPress before 4.7.5, there is insufficient redirect validation in the HTTP...2017
CVE-2017-9066 — Server-Side Request Forgery | cvebase