漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Element Pack Addons for Elementor <= 8.3.15 - Unauthenticated SMTP Header Injection
Vulnerability Description
The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via the `element_pack_contact_form` AJAX action. This is due to insufficient sanitization of newline characters in user-supplied input that gets concatenated into email headers. This makes it possible for unauthenticated attackers to inject arbitrary email headers into emails sent by the contact form.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
对CRLF序列的转义处理不恰当(CRLF注入)
Vulnerability Title
WordPress Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons 输入验证错误漏洞
Vulnerability Description
WordPress Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons是WordPress基金会的一款网页构建器的扩展插件集合。 WordPress Element Pack Addons for Elementor – Elementor Widgets, Elementor Templates, Elementor Addons 8.3.15及之前版本存在输入验证错误漏
CVSS Information
N/A
Vulnerability Type
N/A