漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget
Vulnerability Description
The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is due to the plugin trusting a user-supplied payment amount without server-side validation against the configured ZarinPal widget price. This makes it possible for unauthenticated attackers to submit arbitrary payment amounts to the ZarinPal gateway via the 'amount' parameter.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vulnerability Type
对假设不可变Web参数的外部可控制
Vulnerability Title
WordPress Persian Elementor 输入验证错误漏洞
Vulnerability Description
WordPress Persian Elementor是WordPress基金会开源的一款支持波斯语的网站页面构建工具。 WordPress Persian Elementor 2.8.1及之前版本存在输入验证错误漏洞,该漏洞源于插件信任用户提供的支付金额,未在服务器端对配置的ZarinPal小部件价格进行验证,导致未经身份验证的攻击者可以通过'amount'参数提交任意支付金额到ZarinPal网关。
CVSS Information
N/A
Vulnerability Type
N/A