| ▲ | tptacek 6 hours ago | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
I'm not saying that the vulnerability isn't severe or important to people running Wordpress, only that CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | ferngodfather 5 hours ago | parent | next [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Yeah give me a vuln and I can make it anything between a 2 and 8 quite easily. I routinely see 10s that are "Critical 10.0 CVE (but only if you're using X language with X setting changed from default, and the attacker can MiTM your traffic)" | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ▲ | nicce 6 hours ago | parent | prev [-] | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
> CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to. Not really. They are very good at describing the technical impact. Sometimes pre-condition is very rare and that reduces overall likelihood but for those few it applies, the impact still could be catastrophic. Who wants to risk it if whole business could go down? | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||