CVE-2017-16815: XSS
Published Nov 14, 2017
·Updated
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "urlnew" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.
Affected Software
1 affected component
SnapCreek Duplicator Wordpress=1.2.28
Event History
Nov 14, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for Snap Creek Duplicator plugin?
The vulnerability ID for Snap Creek Duplicator plugin is CVE-2017-16815.
2
What is the severity level of CVE-2017-16815?
The severity level of CVE-2017-16815 is medium with a CVSS score of 6.1.
3
What is the affected software version for CVE-2017-16815?
The affected software version for CVE-2017-16815 is Snap Creek Duplicator plugin version 1.2.28.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2017-16815?
The Common Weakness Enumeration (CWE) ID for CVE-2017-16815 is CWE-79.
5
How can I fix the XSS vulnerability in Snap Creek Duplicator plugin?
To fix the XSS vulnerability in Snap Creek Duplicator plugin, update to version 1.2.30 or later.