TablePress <= 1.8 - Authenticated XML External Entity (XXE)
Sign up to our free email alerts service for instant vulnerability notifications!Affects Plugin
fixed in version 1.8.1
|
References
CVE | 2017-10889 |
URL | https://jvn.jp/en/jp/JVN05398317/index.html |
URL | https://github.com/TobiasBg/TablePress/ |
Classification
Type | XXE |
OWASP Top 10 | A1: Injection |
CWE | CWE-611 |
Miscellaneous
Submitter | ethicalhack3r |
Submitter Website | https://dewhurstsecurity.com/ |
Submitter Twitter | ethicalhack3r |
Views | 575 |
Verified | No |
WPVDB ID | 8963 |
Timeline
Publicly Published | 2017-11-14 (5 months ago) |
Added | 2017-11-23 (5 months ago) |
Last Updated | 2017-11-23 (5 months ago) |
Copyright & License
Copyright | All data and resources contained within this page and this web site is Copyright © The WPScan Team. |
License | Some of this data may be used for non-commercial purposes, however, any potential commercial usage of this data will require a license. If you would like to inquire about a commercial license please contact us. |