漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
RegistrationMagic - Custom Registration Forms <= 3.7.9.2 - PHP Object Injection
Vulnerability Description
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to PHP Object Injection in all versions up to 3.7.9.3 (exclusive) via deserialization of untrusted input from the is_expired_by_date() function. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to fetch a remote file and install it on the site.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
WordPress plugin RegistrationMagic 代码问题漏洞
Vulnerability Description
WordPress等都是(WordPress)基金会的产品。WordPress是一套使用PHP语言开发的博客平台。PHP等都是(PHP)的产品。PHP是一种在服务器端执行的脚本语言。WebSockets ws等都是(WebSockets)开源的产品。ws是一个 Node.js WebSocket 库。 WordPress plugin RegistrationMagic 3.7.9.3之前版本存在代码问题漏洞,该漏洞源于is_expired_by_date函数对不可信输入进行反序列化,可能导致PHP对象注
CVSS Information
N/A
Vulnerability Type
N/A