CVE-2019-16217
published 2019-09-11CVE-2019-16217: WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
PriorityP425medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.53%
72.0th percentile
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | wordpress | < wordpress 5.2.3+dfsg1-1 (bookworm) | wordpress 5.2.3+dfsg1-1 (bookworm) |
| wordpress | wordpress | < 5.2.3 | 5.2.3 |
| wordpress | wordpress | >= 0 < 5.2.3+dfsg1-1 | 5.2.3+dfsg1-1 |
| wordpress | wordpress | >= 0 < 5.2.3+dfsg1-1 | 5.2.3+dfsg1-1 |
| wordpress | wordpress | >= 0 < 5.2.3+dfsg1-1 | 5.2.3+dfsg1-1 |
| wordpress | wordpress | >= 0 < 5.2.3+dfsg1-1 | 5.2.3+dfsg1-1 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-16217: wordpress - WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attach...
vendor_debian·2019·CVSS 6.1
CVE-2019-16217 [MEDIUM] CVE-2019-16217: wordpress - WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attach...
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
Scope: local
bookworm: resolved (fixed in 5.2.3+dfsg1-1)
bullseye: resolved (fixed in 5.2.3+dfsg1-1)
forky: resolved (fixed in 5.2.3+dfsg1-1)
sid: resolved (fixed in 5.2.3+dfsg1-1)
trixie: resolved (fixed in 5.2.3+dfsg1-1)
GHSA
GHSA-3rc6-mcgh-8jqq: WordPress before 5
ghsa_unreviewed·2022-05-24
CVE-2019-16217 [MEDIUM] CWE-79 GHSA-3rc6-mcgh-8jqq: WordPress before 5
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
OSV
CVE-2019-16217: WordPress before 5
osv·2019-09-11·CVSS 6.1
CVE-2019-16217 [MEDIUM] CVE-2019-16217: WordPress before 5
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-16217 wordpress: XSS in media uploads because wp_ajax_upload_attachment is mishandled [epel-7]
bugzilla·2019-11-25·CVSS 6.1
CVE-2019-16217 [MEDIUM] CVE-2019-16217 wordpress: XSS in media uploads because wp_ajax_upload_attachment is mishandled [epel-7]
CVE-2019-16217 wordpress: XSS in media uploads because wp_ajax_upload_attachment is mishandled [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following
Bugzilla
CVE-2019-16217 wordpress: XSS in media uploads because wp_ajax_upload_attachment is mishandled [epel-6]
bugzilla·2019-11-25·CVSS 6.1
CVE-2019-16217 [MEDIUM] CVE-2019-16217 wordpress: XSS in media uploads because wp_ajax_upload_attachment is mishandled [epel-6]
CVE-2019-16217 wordpress: XSS in media uploads because wp_ajax_upload_attachment is mishandled [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following
Bugzilla
CVE-2019-16217 wordpress: XSS in media uploads because wp_ajax_upload_attachment is mishandled
bugzilla·2019-11-25·CVSS 6.1
CVE-2019-16217 [MEDIUM] CVE-2019-16217 wordpress: XSS in media uploads because wp_ajax_upload_attachment is mishandled
CVE-2019-16217 wordpress: XSS in media uploads because wp_ajax_upload_attachment is mishandled
WordPress before 5.2.3 allows XSS in media uploads because wp_ajax_upload_attachment is mishandled.
Reference:
https://core.trac.wordpress.org/changeset/45936
Discussion:
Created wordpress tracking bugs for this issue:
Affects: epel-6 [bug 1776425]
Affects: epel-7 [bug 1776426]
---
Fixed in 5.2.4
https://core.trac.wordpress.org/changeset/45936https://lists.debian.org/debian-lts-announce/2019/10/msg00023.htmlhttps://seclists.org/bugtraq/2020/Jan/8https://wordpress.org/news/2019/09/wordpress-5-2-3-security-and-maintenance-release/https://www.debian.org/security/2020/dsa-4599https://www.debian.org/security/2020/dsa-4677https://core.trac.wordpress.org/changeset/45936https://lists.debian.org/debian-lts-announce/2019/10/msg00023.htmlhttps://seclists.org/bugtraq/2020/Jan/8https://wordpress.org/news/2019/09/wordpress-5-2-3-security-and-maintenance-release/https://www.debian.org/security/2020/dsa-4599https://www.debian.org/security/2020/dsa-4677
2019-09-11
Published