WordPress WPvivid Backup²å¼þ·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-03-30

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬£¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


WPvivid Backup Pulgin < 0.9.37


·ì϶¸ÅÊö


WPvivid BackupÊÇÒ»¸öÃâ·ÑµÄ¶àºÏÒ»±¸·Ý¡¢»¹Ô­ºÍǨáã²å¼þ £¬£¬£¬£¬£¬£¬£¬ËüÓµÓнü4Íò¸ö»îÔ¾×°Öᣡ£¡£¡£¡£ ¡£¡£


½üÈÕ £¬£¬£¬£¬£¬£¬£¬°²È«ÈËÔ±·¢´Ë¿ÌWPvivid Backup²å¼þÖеÄÒ»¸ö·ì϶¿ÉÄܻᱻÓÃÀ´»ñÈ¡Êý¾Ý¿âÒÔ¼°WordPressÍøÕ¾µÄËùÓÐÎļþ¡£¡£¡£¡£¡£ ¡£¡£¶ÔÆä´úÂëµÄ·ÖÎöÏÔʾ £¬£¬£¬£¬£¬£¬£¬Ò»Ð©wp_ajax²Ù×÷δ½øÐÐÊÚȨ²é³­ £¬£¬£¬£¬£¬£¬£¬´Ó¶ø¿Éµ¼Ö¿çÕ¾µãÒªÇóαÔ죨CSRF£©¹¥»÷¡£¡£¡£¡£¡£ ¡£¡£ÊÜÓ°Ïì×î´óµÄ²Ù×÷ÊÇ¡°wp_ajax_wpvivid_add_remote¡± £¬£¬£¬£¬£¬£¬£¬ÕâÒâζ×ÅÓµÓÐÈκνÇÉ«µÄÓû§¶¼Äܹ»Ôö³¤ÐµĴ洢µØÎ»²¢½«ÆäÓÃ×÷ĬÈϱ¸·ÝµØÎ» £¬£¬£¬£¬£¬£¬£¬µ±Ï´α¸·ÝÔËÐÐʱ £¬£¬£¬£¬£¬£¬£¬Õû¸öÊý¾Ý¿â¼°Îļþ½«±»ÉÏ´«µ½¸Ã´æ´¢µØÎ» £¬£¬£¬£¬£¬£¬£¬´Ó¶øÊ¹¹¥»÷ÕßÄܹ»½Ó¼ûÈκÎÎļþ¡£¡£¡£¡£¡£ ¡£¡£


·ì϶ÑéÖ¤


ÔÝÎÞPoC/EXP¡£¡£¡£¡£¡£ ¡£¡£


½¨¸´½¨Òé


Ŀǰ¹Ù·½ÒѰ䲼а汾 £¬£¬£¬£¬£¬£¬£¬Á´½Ó£ºhttps://wordpress.org/plugins/wpvivid-backuprestore/¡£¡£¡£¡£¡£ ¡£¡£


²Î¿¼Á´½Ó


https://www.webarxsecurity.com/vulnerability-in-wpvivid-backup-plugin-can-lead-to-database-leak/