CVE-2017-14990
Summary
| CVE | CVE-2017-14990 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-03 01:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | WordPress 4.8.2 stores cleartext wp_signups.activation_key values (but stores the analogous wp_users.user_activation_key values as hashes), which might make it easier for remote attackers to hijack unactivated user accounts by leveraging database read access (such as access gained through an unspecified SQL injection vulnerability). |
Risk And Classification
Problem Types: CWE-312
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Wordpress | Wordpress | 4.8.2 | All | All | All |
| Application | Wordpress | Wordpress | 4.8.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Debian -- Security Information -- DSA-3997-1 wordpress | DEBIAN | www.debian.org | Third Party Advisory |
| #38474 (wp_signups.activation_key stores activation keys in plain text) – WordPress Trac | MISC | core.trac.wordpress.org | Exploit, Issue Tracking, Third Party Advisory |
| WordPress 'wp_signups.activation_key' Storage Method May Facilitate Remote Users in Hijacking User Accounts That Are Awaiting Activation - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.