WordPress Core < 3.5.2 - XXE Injection

2013-06-21 00:00
Anonymous

Strategic Overview

Status
Patched in 3.5.2
Affected CoreWordPress 3.5
Affected Version<= 3.5.1
CVSS5.4Medium
CVECVE-2013-2202
View all WordPress 3.5 vulnerabilities

Vulnerability Overview

WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Technical Analysis

REMEDIATION: Update to version 3.5.2, or a newer patched version --- IDENTIFIER: CWE-611 (Improper Restriction of XML External Entity Reference) The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C