ID

VAR-201908-1202


CVE

CVE-2015-9293


TITLE

WordPress for all-in-one-wp-security-and-firewall Plug-in vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2019-007699

DESCRIPTION

The all-in-one-wp-security-and-firewall plugin before 3.9.8 for WordPress has XSS in the unlock request feature. WordPress for all-in-one-wp-security-and-firewall The plug-in contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. The vulnerability stems from the lack of correct validation of client data in WEB applications. An attacker could exploit this vulnerability to execute client code

Trust: 1.71

sources: NVD: CVE-2015-9293 // JVNDB: JVNDB-2019-007699 // VULHUB: VHN-87254

AFFECTED PRODUCTS

vendor:tipsandtricks hqmodel:all in one wp security \& firewallscope:ltversion:3.9.8

Trust: 1.0

vendor:tips and tricks hqmodel:all in one wp security & firewallscope:ltversion:3.9.8

Trust: 0.8

sources: JVNDB: JVNDB-2019-007699 // NVD: CVE-2015-9293

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-9293
value: MEDIUM

Trust: 1.0

NVD: CVE-2015-9293
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201908-839
value: MEDIUM

Trust: 0.6

VULHUB: VHN-87254
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-9293
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-87254
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2015-9293
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-87254 // JVNDB: JVNDB-2019-007699 // CNNVD: CNNVD-201908-839 // NVD: CVE-2015-9293

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-87254 // JVNDB: JVNDB-2019-007699 // NVD: CVE-2015-9293

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201908-839

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201908-839

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-007699

PATCH

title:All In One WP Security & Firewallurl:https://wordpress.org/plugins/all-in-one-wp-security-and-firewall/#developers

Trust: 0.8

title:WordPress all-in-one-wp-security-and-firewall Fixes for plugin cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=96530

Trust: 0.6

sources: JVNDB: JVNDB-2019-007699 // CNNVD: CNNVD-201908-839

EXTERNAL IDS

db:NVDid:CVE-2015-9293

Trust: 2.5

db:JVNDBid:JVNDB-2019-007699

Trust: 0.8

db:CNNVDid:CNNVD-201908-839

Trust: 0.7

db:VULHUBid:VHN-87254

Trust: 0.1

sources: VULHUB: VHN-87254 // JVNDB: JVNDB-2019-007699 // CNNVD: CNNVD-201908-839 // NVD: CVE-2015-9293

REFERENCES

url:https://wordpress.org/plugins/all-in-one-wp-security-and-firewall/#developers

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2015-9293

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-9293

Trust: 0.8

sources: VULHUB: VHN-87254 // JVNDB: JVNDB-2019-007699 // CNNVD: CNNVD-201908-839 // NVD: CVE-2015-9293

SOURCES

db:VULHUBid:VHN-87254
db:JVNDBid:JVNDB-2019-007699
db:CNNVDid:CNNVD-201908-839
db:NVDid:CVE-2015-9293

LAST UPDATE DATE

2024-11-23T21:59:43.371000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-87254date:2019-08-16T00:00:00
db:JVNDBid:JVNDB-2019-007699date:2019-08-19T00:00:00
db:CNNVDid:CNNVD-201908-839date:2019-08-19T00:00:00
db:NVDid:CVE-2015-9293date:2024-11-21T02:40:16.363

SOURCES RELEASE DATE

db:VULHUBid:VHN-87254date:2019-08-13T00:00:00
db:JVNDBid:JVNDB-2019-007699date:2019-08-19T00:00:00
db:CNNVDid:CNNVD-201908-839date:2019-08-13T00:00:00
db:NVDid:CVE-2015-9293date:2019-08-13T17:15:11.627