CVE-2017-14313: XSS
Published Sep 12, 2017
·Updated
The shibbolethloginform function in shibboleth.php in the Shibboleth plugin before 1.8 for WordPress is prone to an XSS vulnerability due to improper use of addqueryarg().
Affected Software
1 affected component
Shibboleth Project Shibboleth Wordpress<=1.7
Remediation
Patch Available
Event History
Sep 12, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14313?
CVE-2017-14313 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2017-14313?
To fix CVE-2017-14313, update the Shibboleth plugin to version 1.8 or later.
3
What causes CVE-2017-14313?
CVE-2017-14313 is caused by improper use of the add_query_arg() function leading to XSS vulnerabilities.
4
Which versions of the Shibboleth plugin are affected by CVE-2017-14313?
CVE-2017-14313 affects versions of the Shibboleth plugin prior to 1.8.
5
Is CVE-2017-14313 exploitable?
Yes, CVE-2017-14313 is exploitable and can allow attackers to execute arbitrary scripts in the context of a user session.