漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX
Vulnerability Description
Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal methods and write arbitrary data to the plugin's External Scripts global setting. Attackers can inject malicious JavaScript through the External Scripts setting that executes in the browsers of all checkout page visitors.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vulnerability Type
授权机制缺失
Vulnerability Title
WordPress plugin Funnel Builder for WooCommerce Checkout 安全漏洞
Vulnerability Description
WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。WordPress plugin是一个应用插件。 WordPress plugin Funnel Builder for WooCommerce Checkout 3.15.0.3之前版本存在安全漏洞,该漏洞源于公共结账端点缺少授权,可能导致未认证攻击者调用内部方法并将任意数据写入插件的外部脚本全局
CVSS Information
N/A
Vulnerability Type
N/A