漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Cost Calculator Builder <= 4.0.11 - Unauthenticated Sensitive Information Exposure of Payment Gateway Secret Keys
Vulnerability Description
The Cost Calculator Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.0.11 via the (template body). This makes it possible for unauthenticated attackers to extract the plaintext Stripe secret key, Razorpay secret key, and PayPal client_secret embedded in the page source of any page containing a calculator, enabling full control of the merchant's payment gateway accounts. This exposure only occurs when the 'use in all calculators' option is enabled for one or more payment gateways in the plugin's global settings.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
信息暴露
Vulnerability Title
stylemixthemes cost calculator builder 信息泄露漏洞
Vulnerability Description
stylemixthemes cost calculator builder是stylemixthemes公司的一款成本估算与报价生成插件。 stylemixthemes cost calculator builder 4.0.11及之前版本存在信息泄露漏洞,该漏洞源于通过模板主体导致敏感信息暴露,可使未经身份验证的攻击者从包含计算器的页面源代码中提取明文Stripe secret key、Razorpay secret key和PayPal client_secret,从而完全控制商户的支付网关账户。
CVSS Information
N/A
Vulnerability Type
N/A