WordPress Easy Digital Downloads是WordPress基金会的一款数字化文件下载管理软件。 WordPress Easy Digital Downloads 3.6.9及之前版本存在任意文件上传漏洞,该漏洞源于edd_do_ajax_import_file_upload()函数对文件类型验证不足,仅检查客户端提供的$_FILES['edd-import-file']['type'] Content-Type头,导致经过身份验证的攻击者可上传任意文件,可能导致远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| smub | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | ≤ 3.6.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| smub | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | 0 ~ 3.6.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet