漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload
Vulnerability Description
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Product Addons and Product Options With Custom Fields 跨站脚本漏洞
Vulnerability Description
WordPress Product Addons and Product Options With Custom Fields是WordPress基金会的一款产品定制字段与附加选项的插件。 WordPress Product Addons and Product Options With Custom Fields 1.6.15之前版本存在跨站脚本漏洞,该漏洞源于未限制未经验证的用户对文件上传端点的访问,接受并以内联方式存储和提供SVG文件,可能导致未经验证的攻击者上传恶意SVG文件,其中嵌入的脚本会在任
CVSS Information
N/A
Vulnerability Type
N/A