WordPress WPvivid Backup²å¼þ·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-03-30·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
WPvivid Backup Pulgin < 0.9.37
·ì϶¸ÅÊö
WPvivid BackupÊÇÒ»¸öÃâ·ÑµÄ¶àºÏÒ»±¸·Ý¡¢»¹ÔºÍǨáã²å¼þ£¬£¬£¬£¬£¬£¬£¬ËüÓµÓнü4Íò¸ö»îÔ¾×°Öᣡ£¡£¡£¡£¡£¡£
½üÈÕ£¬£¬£¬£¬£¬£¬£¬°²È«ÈËÔ±·¢´Ë¿ÌWPvivid Backup²å¼þÖеÄÒ»¸ö·ì϶¿ÉÄܻᱻÓÃÀ´»ñÈ¡Êý¾Ý¿âÒÔ¼°WordPressÍøÕ¾µÄËùÓÐÎļþ¡£¡£¡£¡£¡£¡£¡£¶ÔÆä´úÂëµÄ·ÖÎöÏÔʾ£¬£¬£¬£¬£¬£¬£¬Ò»Ð©wp_ajax²Ù×÷δ½øÐÐÊÚȨ²é³£¬£¬£¬£¬£¬£¬£¬´Ó¶ø¿Éµ¼Ö¿çÕ¾µãÒªÇóαÔ죨CSRF£©¹¥»÷¡£¡£¡£¡£¡£¡£¡£ÊÜÓ°Ïì×î´óµÄ²Ù×÷ÊÇ¡°wp_ajax_wpvivid_add_remote¡±£¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÓµÓÐÈκνÇÉ«µÄÓû§¶¼Äܹ»Ôö³¤ÐµĴ洢µØÎ»²¢½«ÆäÓÃ×÷ĬÈϱ¸·ÝµØÎ»£¬£¬£¬£¬£¬£¬£¬µ±Ï´α¸·ÝÔËÐÐʱ£¬£¬£¬£¬£¬£¬£¬Õû¸öÊý¾Ý¿â¼°Îļþ½«±»ÉÏ´«µ½¸Ã´æ´¢µØÎ»£¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»½Ó¼ûÈκÎÎļþ¡£¡£¡£¡£¡£¡£¡£
·ì϶ÑéÖ¤
ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£¡£¡£
½¨¸´½¨Òé
Ŀǰ¹Ù·½ÒѰ䲼а汾£¬£¬£¬£¬£¬£¬£¬Á´½Ó£ºhttps://wordpress.org/plugins/wpvivid-backuprestore/¡£¡£¡£¡£¡£¡£¡£
²Î¿¼Á´½Ó
https://www.webarxsecurity.com/vulnerability-in-wpvivid-backup-plugin-can-lead-to-database-leak/


¾©¹«Íø°²±¸11010802024551ºÅ