MEDIUM
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash
Published Sep 11, 2019
6.1
MEDIUMCVSS 3.1
EPSS 2.55%
Description
In WordPress before 5.2.3, validation and sanitization of a URL in wp_validate_redirect in wp-includes/pluggable.php could lead to an open redirect if a provided URL path does not start with a forward slash.
Affected products
No data.
Configuration 2
OR
- 8.0
- 9.0
- 10.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- https://core.trac.wordpress.org/changeset/45971 PatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7032 Advisory
- https://github.com/WordPress/WordPress/commit/c86ee39ff4c1a79b93c967eb88522f5c09614a28 PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/10/msg00023.html mailing-listMailing ListThird Party Advisory
- https://medium.com/@theodorejackson.us/rediscovering-an-old-vulnerability-cve-2019-16220-d25cc441752f
- https://seclists.org/bugtraq/2020/Jan/8 mailing-listMailing ListThird Party Advisory
- https://wordpress.org/news/2019/09/wordpress-5-2-3-security-and-maintenance-release/ Release NotesVendor Advisory
- https://wpvulndb.com/vulnerabilities/9863 Third Party Advisory
- https://www.debian.org/security/2020/dsa-4599 vendor-advisoryThird Party Advisory
- https://www.debian.org/security/2020/dsa-4677 vendor-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://core.trac.wordpress.org/changeset/45971 | PatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-7032 | Advisory | |
| https://github.com/WordPress/WordPress/commit/c86ee39ff4c1a79b93c967eb88522f5c09614a28 | PatchThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2019/10/msg00023.html | mailing-listMailing ListThird Party Advisory | |
| https://medium.com/@theodorejackson.us/rediscovering-an-old-vulnerability-cve-2019-16220-d25cc441752f | ||
| https://seclists.org/bugtraq/2020/Jan/8 | mailing-listMailing ListThird Party Advisory | |
| https://wordpress.org/news/2019/09/wordpress-5-2-3-security-and-maintenance-release/ | Release NotesVendor Advisory | |
| https://wpvulndb.com/vulnerabilities/9863 | Third Party Advisory | |
| https://www.debian.org/security/2020/dsa-4599 | vendor-advisoryThird Party Advisory | |
| https://www.debian.org/security/2020/dsa-4677 | vendor-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 11, 2019
Updated Aug 21, 2024
Reserved Sep 11, 2019
Link CVE-2019-16220
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-7032 Assigner mitre
Published Sep 11, 2019
Updated Aug 21, 2024
Exploited since n/a
Link EUVD-2019-7032