ZeroHour

CVE-2017-9061

CVSS 3.0
6.1 medium
EPSS
2%p79
Published
()
Modified
Description

In WordPress before 4.7.5, a cross-site scripting (XSS) vulnerability exists when attempting to upload very large files, because the error message does not properly restrict presentation of the filename.

Vendors
wordpressdebian
Products
wordpress, debian linux
Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.