VulnerabilityModified
CVE-2013-2203
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.
MEDIUM 4.3EPSS 2.03%
Does this matter?
Lower severity and a low EPSS score (2.03%). Track it; it rarely justifies an emergency change on its own.
Description
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 2.03% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- wordpress/wordpress
- Source
- secalert@redhat.com
References
- http://codex.wordpress.org/Version_3.5.2
- http://wordpress.org/news/2013/06/wordpress-3-5-2/Vendor Advisory
- http://www.debian.org/security/2013/dsa-2718
- https://bugzilla.redhat.com/show_bug.cgi?id=976784
- http://codex.wordpress.org/Version_3.5.2
- http://wordpress.org/news/2013/06/wordpress-3-5-2/Vendor Advisory
- http://www.debian.org/security/2013/dsa-2718
- https://bugzilla.redhat.com/show_bug.cgi?id=976784
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.