漏洞标题
WordPress Popular Posts <= 5.3.2 认证任意文件上传漏洞
漏洞描述信息
WordPress Popular Posts <= 5.3.2 认证任意文件上传漏洞
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
漏洞描述信息
The WordPress Popular Posts WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/src/Image.php file which makes it possible for attackers with contributor level access and above to upload malicious files that can be used to obtain remote code execution, in versions up to and including 5.3.2.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
危险类型文件的不加限制上传
漏洞标题
WordPress 代码问题漏洞
漏洞描述信息
WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress plugin WordPress Popular Posts 存在代码问题漏洞,该漏洞源于 ~/src/Image.php 文件中的输入文件类型验证不足。这使得具有贡献者级别及以上访问权限的攻击者可以通过上传可以使用的恶意文件来进行远程代码执行。
CVSS信息
N/A
漏洞类别
代码问题