CVE-2017-16815
Last modified
CVE-2017-16815 is a vulnerability of currently unknown severity. installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.. EPSS estimates a 1.02% chance of exploitation in the next 30 days.
Description
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Snapcreek | Duplicator | 1.2.28 |
References
- https://packetstormsecurity.com/files/144914/WordPress-Duplicator-Migration-1.2.28-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://snapcreek.com/duplicator/docs/changelogRelease Notes, Vendor Advisory
- https://packetstormsecurity.com/files/144914/WordPress-Duplicator-Migration-1.2.28-Cross-Site-Scripting.htmlThird Party Advisory, VDB Entry
- https://snapcreek.com/duplicator/docs/changelogRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-16815?
How severe is CVE-2017-16815?
How do I fix CVE-2017-16815?
Are you affected by CVE-2017-16815?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
