漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Demi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory Copy
Vulnerability Description
The Demi – One Click Demo Import, WP Backup & Site Migration plugin for WordPress is vulnerable to Arbitrary Directory Copy in all versions up to, and including, 0.0.8 via the handle_restore_step function. This is due to missing HTTP access controls on the wp-content/uploads/demi-backup-state/ directory, which exposes the cryptographic restore key used to both authenticate the unauthenticated AJAX handler and forge signed restore-state envelopes. This makes it possible for unauthenticated attackers to copy arbitrary files to attacker-controlled destinations on the server. An active restore operation must have been initiated, which writes the .restore_key and .restore_step_token files to the public upload directory, before the exposed secrets can be harvested and chained to achieve unauthenticated arbitrary file copy.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
信息暴露
Vulnerability Title
WordPress Demi 信息泄露漏洞
Vulnerability Description
WordPress Demi是WordPress基金会开源的一款功能强大的 WordPress 演示导入、备份和网站迁移插件。 WordPress Demi 0.0.8及之前版本存在信息泄露漏洞,该漏洞源于handle_restore_step函数缺少HTTP访问控制,导致wp-content/uploads/demi-backup-state/目录暴露加密恢复密钥,可能使未经身份验证的攻击者复制任意文件到攻击者控制的服务器位置。
CVSS Information
N/A
Vulnerability Type
N/A