漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ProSolution WP Client <= 2.0.8 - Unauthenticated Arbitrary File Deletion via 'newfilename' and 'filename' Parameters
Vulnerability Description
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDeleteProcess function in all versions up to, and including, 2.0.8. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). An attacker must first call the proSol_fileUploadModalProcess handler to poison their own session with a path-traversal key, then call proSol_fileDeleteProcess with that key as the filename parameter; both steps require only the publicly exposed frontend nonce.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
WordPress ProSolution WP Client 路径遍历漏洞
Vulnerability Description
WordPress ProSolution WP Client是WordPress基金会的一款网站内容管理系统的客户端组件。 WordPress ProSolution WP Client 2.0.8及之前版本存在路径遍历漏洞,该漏洞源于proSol_fileDeleteProcess函数文件路径验证不足,可能导致未经身份验证的攻击者删除服务器上的任意文件,进而可能导致远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A