WordPress WPvivid Backup²å¼þÎó²îΣº¦Í¨¸æ
Ðû²¼Ê±¼ä 2020-03-30Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
WPvivid Backup Pulgin < 0.9.37
Îó²î¸ÅÊö
WPvivid BackupÊÇÒ»¸öÃâ·ÑµÄ¶àºÏÒ»±¸·Ý¡¢»¹ÔºÍǨáã²å¼þ£¬Ëü¾ßÓнü4Íò¸ö»îÔ¾×°Öá£
¿ËÈÕ£¬Çå¾²Ö°Ô±·¢Ã÷ÔÚWPvivid Backup²å¼þÖеÄÒ»¸öÎó²î¿ÉÄܻᱻÓÃÀ´»ñÈ¡Êý¾Ý¿âÒÔ¼°WordPressÍøÕ¾µÄËùÓÐÎļþ¡£¶ÔÆä´úÂëµÄÆÊÎöÏÔʾ£¬Ò»Ð©wp_ajax²Ù×÷δ¾ÙÐÐÊÚȨ¼ì²é£¬´Ó¶ø¿Éµ¼Ö¿çÕ¾µãÇëÇóαÔ죨CSRF£©¹¥»÷¡£ÊÜÓ°Ïì×î´óµÄ²Ù×÷ÊÇ¡°wp_ajax_wpvivid_add_remote¡±£¬ÕâÒâζמßÓÐÈκνÇÉ«µÄÓû§¶¼¿ÉÒÔÌí¼ÓеĴ洢λÖò¢½«ÆäÓÃ×÷ĬÈϱ¸·ÝλÖ㬵±Ï´α¸·ÝÔËÐÐʱ£¬Õû¸öÊý¾Ý¿â¼°Îļþ½«±»ÉÏ´«µ½¸Ã´æ´¢Î»Ö㬴ӶøÊ¹¹¥»÷Õß¿ÉÒÔ»á¼ûÈκÎÎļþ¡£
Îó²îÑéÖ¤
ÔÝÎÞPoC/EXP¡£
ÐÞ¸´½¨Òé
ÏÖÔÚ¹Ù·½ÒÑÐû²¼Ð°汾£¬Á´½Ó£ºhttps://wordpress.org/plugins/wpvivid-backuprestore/¡£
²Î¿¼Á´½Ó
https://www.webarxsecurity.com/vulnerability-in-wpvivid-backup-plugin-can-lead-to-database-leak/


¾©¹«Íø°²±¸11010802024551ºÅ