漏洞标题
Uncode <= 2.9.1.6 - 经认证(用户+)任意文件读取漏洞
漏洞描述信息
WordPress的Uncode主题在所有版本(包括)2.9.1.6及之前版本中存在任意文件读取漏洞。该漏洞源于'uncode_recordMedia'函数中对输入验证不足。这使得具有订阅者级别及以上权限的经过身份验证的攻击者能够在服务器上读取任意文件。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
漏洞类别
输入验证不恰当
漏洞标题
Uncode <= 2.9.1.6 - Authenticated (Subscriber+) Arbitrary File Read in uncode_recordMedia
漏洞描述信息
The Uncode theme for WordPress is vulnerable to arbitrary file read due to insufficient input validation in the 'uncode_recordMedia' function in all versions up to, and including, 2.9.1.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary files on the server.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
漏洞类别
输入验证不恰当