CVE-2013-2203

medium

Description

WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an XMLHttpRequest error message.

References

https://bugzilla.redhat.com/show_bug.cgi?id=976784

http://www.debian.org/security/2013/dsa-2718

http://wordpress.org/news/2013/06/wordpress-3-5-2/

http://codex.wordpress.org/Version_3.5.2

Details

Source: Mitre, NVD

Published: 2013-07-08

Updated: 2013-09-10

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium