Cross-site Scripting Vulnerability in WordPress MU by Automattic
CVE-2009-1030

Currently unrated

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
20 March 2009

Summary

The vulnerability in WordPress MU allows remote attackers to exploit the 'choose_primary_blog' function, enabling them to execute arbitrary web scripts or HTML. This is achieved through the manipulation of the HTTP Host header, which can lead to unauthorized actions on behalf of a user. Proper sanitization of input and rigorous validation measures are crucial in mitigating risks associated with this vulnerability in web applications.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.