漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data
Vulnerability Description
The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to the `bp_unserialize_profile_field()` function using `@unserialize()` without the `allowed_classes` parameter on user-controlled XProfile field data. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary PHP objects via XProfile textbox fields, which could lead to remote code execution if a suitable POP chain is available in the WordPress environment.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
可信数据的反序列化
Vulnerability Title
WordPress BuddyPress 反序列化注入漏洞
Vulnerability Description
buddypress是Buddypress团队开源的一个社交网络插件。 WordPress BuddyPress 14.5.0及之前版本存在反序列化注入漏洞,该漏洞源于bp_unserialize_profile_field()函数对用户控制的XProfile字段数据使用@unserialize()时未设置allowed_classes参数,导致未经授权的反序列化,使得经过身份验证的攻击者能够注入任意PHP对象,可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A