Vulnerability Description
wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting of a site.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | < 4.9.1 |
| Debian | Debian Linux | 7.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/102024Third Party AdvisoryVDB Entry
- https://codex.wordpress.org/Version_4.9.1PatchRelease NotesVendor Advisory
- https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43dPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/12/msg00019.htmlMailing ListThird Party Advisory
- https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-releRelease NotesVendor Advisory
- https://wpvulndb.com/vulnerabilities/8968Third Party AdvisoryVDB Entry
- https://www.debian.org/security/2018/dsa-4090Third Party Advisory
- http://www.securityfocus.com/bid/102024Third Party AdvisoryVDB Entry
- https://codex.wordpress.org/Version_4.9.1PatchRelease NotesVendor Advisory
- https://github.com/WordPress/WordPress/commit/3713ac5ebc90fb2011e98dfd691420f43dPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2017/12/msg00019.htmlMailing ListThird Party Advisory
- https://wordpress.org/news/2017/11/wordpress-4-9-1-security-and-maintenance-releRelease NotesVendor Advisory
- https://wpvulndb.com/vulnerabilities/8968Third Party AdvisoryVDB Entry
- https://www.debian.org/security/2018/dsa-4090Third Party Advisory
FAQ
What is CVE-2017-17093?
CVE-2017-17093 is a vulnerability with a CVSS score of 5.4 (MEDIUM). wp-includes/general-template.php in WordPress before 4.9.1 does not properly restrict the lang attribute of an HTML element, which might allow attackers to conduct XSS attacks via the language setting...
How severe is CVE-2017-17093?
CVE-2017-17093 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17093?
Check the references section above for vendor advisories and patch information. Affected products include: Wordpress Wordpress, Debian Debian Linux.