WordPress 5.1 CSRF µ¼ÖÂÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-15

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º 

WordPress 5.1.1 ֮ǰµÄ°æ±¾ (²»º¬ 5.1.1)


·ì϶¸ÅÊö


3 Ô 13 ÈÕ£¬£¬£¬£¬£¬£¬£¬£¬RIPSTECH °ä²¼ÁË WordPress 5.1 CSRF ·ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÄÚÈÝϸ½Ú¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýºýŪָ±ê²©¿ÍµÄÖÎÀíÔ±½Ó¼û¹¥»÷ÕßÉèÖõÄÍøÕ¾À´ÊÕÊÜÈÎºÎÆôÓÃÁËÆÀÂÛµÄWordPressÍøÕ¾¡£¡£¡£¡£¡£¡£Ò»µ©Êܺ¦ÖÎÀíÔ±½Ó¼û¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬£¬£¬£¬¾Í»áÔÚºó¶ÜÕë¶ÔÖ¸±êWordPress²©¿ÍÔËÐпçÕ¾µãÒªÇóαÔ죨CSRF£©·ì϶£¬£¬£¬£¬£¬£¬£¬£¬¶ø²»»áÊܵ½Êܺ¦ÕßÈ·°ÑÎÈ¡£¡£¡£¡£¡£¡£CSRF·ì϶ÀûÓÃÁ˶à¸öÂß¼­È±µãºÍËãÕÊÃýÎ󣬣¬£¬£¬£¬£¬£¬£¬ÕâЩÃýÎóÔÚ×éӦʱ»áµ¼ÖÂÔ¶³ÌÖ´ÐдúÂëºÍÆëÈ«µÄÕ¾µãÊÕÊÜ¡£¡£¡£¡£¡£¡£


·ì϶´æÔÚÓÚ5.1.1֮ǰµÄWordPress°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬£¬Äܹ»Ê¹ÓÃĬÈÏÉèÖýøÐÐÀûÓᣡ£¡£¡£¡£¡£


³¬¹ý33£¥µÄ»¥ÁªÍøÍøÕ¾Ê¹ÓÃWordPress¡£¡£¡£¡£¡£¡£¿£¿£¿£¿£¿£¿£Ë¼¿¼µ½ÆÀÂÛÊDz©¿ÍµÄÖ÷ÌâÖ°Äܲ¢ÇÒĬÈÏÇé¿öÏÂÒÑÆôÓ㬣¬£¬£¬£¬£¬£¬£¬¸Ã·ì϶»áÓ°ÏìÊý°ÙÍò¸öÍøÕ¾¡£¡£¡£¡£¡£¡£


·ì϶ÏêÇé


ÔÚ WordPress µÄ´¦Öùý³ÌÖÐÓÉÓÚҪʵÏÖһЩ¸öÐÔµÄÔ­Òò£¬£¬£¬£¬£¬£¬£¬£¬WordPress²¢Ã»ÓÐÕë¶ÔÆÀÂ۵İ䲼×öCSRFÏÞ¶È£¬£¬£¬£¬£¬£¬£¬£¬ÄÇô¹¥»÷Õ߾ͿÉÄÜʹÓÃCSRF¹¥»÷À´¹¥»÷WordPressÖÎÀíԱʹÆäͨ¹ýÆäȨÏÞ´´½¨ÆÀÂÛ¡£¡£¡£¡£¡£¡£


WordPressÊÔͼͨ¹ýÔÚÆÀÂÛ±íµ¥ÖÐΪÖÎÀíÔ±ÌìÉúÒ»¸ö¶î±íµÄËæ»úÊýÀ´½â¾öÕâ¸öÎÊÌâ¡£¡£¡£¡£¡£¡£µ±ÖÎÀíÔ±Ìá½»ÆÀÂÛ²¢ÌṩÓÐЧµÄËæ»úÊýʱ£¬£¬£¬£¬£¬£¬£¬£¬ÆÀÂÛ½«ÔÚ²»¾­¹ýÈκÎËãÕʺ¯ÊýµÄÇé¿öÏ´´½¨¡£¡£¡£¡£¡£¡£ÈôÊÇËæ»úÊýÎÞЧ£¬£¬£¬£¬£¬£¬£¬£¬ÆÀÂÛÈԻᴴ½¨£¬£¬£¬£¬£¬£¬£¬£¬µ«»á±»ËãÕʺ¯Êý´¦Öᣡ£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


Äܹ»¿´µ½ÆÀÂÛͨ³£ÊÇwp_filter_ksesÀ´ÕƹÜËãÕʵÄ¡£¡£¡£¡£¡£¡£wp_filter_kses½öÔÊÐí½öÓÐ href ÊôÐ﵀ a ±êÇ©¡£¡£¡£¡£¡£¡£


ÈôÊÇÊÇÈçÏÂÕâÖÖÇé¿ö£º´´½¨ÆÀÂÛµÄÓû§Õ¼ÓÐunfiltered_htmlȨÏÞ£¬£¬£¬£¬£¬£¬£¬£¬²¢ÇÒûÓÐÌṩÓÐЧµÄËæ»úÊý£¬£¬£¬£¬£¬£¬£¬£¬ÔòÓà wp_filter_post_kses À´ËãÕÊ×¢½â¡£¡£¡£¡£¡£¡£


wp_filter_post_kses ËäÈÔ»áɾ³ýÈκοÉÄܵ¼Ö¿çÕ¾µã¾ç±¾·ì϶µÄ HTML ÏóÕ÷ºÍÊôÐÔ¡£¡£¡£¡£¡£¡£µ«ÔÊÐíÁËһЩÆäËûµÄ³£¼ûÊôÐԺñÈrel¡£¡£¡£¡£¡£¡£


WordPress ÔÚ´¦ÖÃÆÀÂÛÖÐµÄ a ±êÇ©µÄÊôÐÔʱ³½»áͨ¹ýÈçÏ´úÂ룬£¬£¬£¬£¬£¬£¬£¬½«ÊôÐÔ´¦ÖÃΪ¼üÖµ¶Ô¹ØÏµ¼üÊÇÊôÐÔµÄÃû³Æ£¬£¬£¬£¬£¬£¬£¬£¬ÖµÊÇÊôÐÔÖµ¡£¡£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website



WordPress ¶øºó²é³­relÊôÐÔÊÇ·ñ±»ÉèÖᣡ£¡£¡£¡£¡£Ö»ÓÐͨ¹ý wp_filter_post_kses ¹ýÂË×¢½â£¬£¬£¬£¬£¬£¬£¬£¬ÄÜÁ¦ÉèÖôËÊôÐÔ¡£¡£¡£¡£¡£¡£°´ÈçÏ·½Ê½´¦Öᣡ£¡£¡£¡£¡£


8827Ì«Ñô¼¯ÍÅ(Macau)¹É·ÝÓÐÏÞ¹«Ë¾-Official website


±êÌâÊôÐÔÖµÓÃË«ÒýºÅÀ¨ÆðÀ´(µÚ 3018 ÐÐ)¡£¡£¡£¡£¡£¡£ÕâÒâζ׏¥»÷ÕßÄܹ»Í¨¹ý×¢Èë¹ØºÏtitleÊôÐԵĶî±íË«ÒýºÅÀ´×¢Èë¶î±íµÄ HTML ÊôÐÔ¡£¡£¡£¡£¡£¡£


ÀýÈ磺title='XSS " onmouseover=alert(1) id="'

ÀíÂÛÉÏ ½«»áÔì³É

¶øºóÔÚ¾­¹ý´¦Öúó¸ÃÆÀÂÛ¼´»á±» WordPress ´æ´¢ÈëÊý¾Ý¿â¡£¡£¡£¡£¡£¡£


¹¥»÷ÕßÔÚ´´½¨¶ñÒâ×¢½âºó»ñȡԶ³ÌÖ´ÐдúÂëµÄÏÂÒ»²½ÊÇ»ñÈ¡ÖÎÀíÔ±Ö´ÐÐ×¢ÈëµÄJavaScript¡£¡£¡£¡£¡£¡£ÆÀÂÛÏÔʾÔÚÖ¸±êWordPress²©¿ÍµÄǰ¶Ë¡£¡£¡£¡£¡£¡£ WordPress×ÔÉí²»ÊÜX-Frame-Options±êÍ·µÄ±£»£»£»£» £»£» £» £»¤¡£¡£¡£¡£¡£¡£ÕâÒâζ×ÅÆÀÂÛÄܹ»ÏÔʾÔÚ¹¥»÷ÕßÍøÕ¾Éϵݵ²Ø