You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to
Source: wordpress
Version: 6.2+dfsg1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: car...@debian.org, Debian Security Team <te...@security.debian.org>
Control: found -1 6.1.1+dfsg1-1
Hi,
The following vulnerability was published for wordpress.
CVE-2023-2745[0]:
| WordPress Core is vulnerable to Directory Traversal in versions up to,
| and including, 6.2, via the &#8216;wp_lang&#8217; parameter.
| This allows unauthenticated attackers to access and load arbitrary
| translation files. In cases where an attacker is able to upload a
| crafted translation file onto the site, such as via an upload form,
| this could be also used to perform a Cross-Site Scripting attack.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.