漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Export All URLs < 4.3 - Private/Draft Post/Page Title Disclosure via CSRF
Vulnerability Description
The Export All URLs WordPress plugin before 4.3 does not have CSRF in place when exporting data, which could allow attackers to make a logged in admin export all posts and pages (including private and draft) into an arbitrary CSV file, which the attacker can then download and retrieve the list of titles for example
CVSS Information
N/A
Vulnerability Type
跨站请求伪造(CSRF)
Vulnerability Title
WordPress Export All URLs plugin跨站请求伪造漏洞
Vulnerability Description
WordPress等都是WordPress(Wordpress)基金会的产品。WordPress是一套使用PHP语言开发的博客平台。WordPress plugin等都是(WordPress)开源的产品。WordPress plugin是一个应用插件。Atlas Gondal Export All URLs等都是(Atlas Gondal)个人开发者的产品。Export All URLs是一个 WordPress 插件。 WordPress Export All URLs plugin存在跨站请求伪造漏洞
CVSS Information
N/A
Vulnerability Type
N/A