CVE-2014-9037

critical

Description

WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash.

References

https://wordpress.org/news/2014/11/wordpress-4-0-1/

http://www.securitytracker.com/id/1031243

http://www.mandriva.com/security/advisories?name=MDVSA-2014:233

http://www.debian.org/security/2014/dsa-3085

http://openwall.com/lists/oss-security/2014/11/25/12

http://advisories.mageia.org/MGASA-2014-0493.html

Details

Source: Mitre, NVD

Published: 2014-11-25

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical