Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via a dashboard_incoming_links edit action.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | 3.4.2 |
Related Weaknesses (CWE)
References
- http://openwall.com/lists/oss-security/2012/09/25/15
- http://packetstormsecurity.org/files/116785/WordPress-3.4.2-Cross-Site-Request-FExploit
- http://secunia.com/advisories/50715Vendor Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=436198Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=860261
- http://openwall.com/lists/oss-security/2012/09/25/15
- http://packetstormsecurity.org/files/116785/WordPress-3.4.2-Cross-Site-Request-FExploit
- http://secunia.com/advisories/50715Vendor Advisory
- https://bugs.gentoo.org/show_bug.cgi?id=436198Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=860261
FAQ
What is CVE-2012-4448?
CVE-2012-4448 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Cross-site request forgery (CSRF) vulnerability in wp-admin/index.php in WordPress 3.4.2 allows remote attackers to hijack the authentication of administrators for requests that modify an RSS URL via ...
How severe is CVE-2012-4448?
CVE-2012-4448 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-4448?
Check the references section above for vendor advisories and patch information. Affected products include: Wordpress Wordpress.