漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
SureCart <= 4.2.3 - Unauthenticated Linked WordPress Account Takeover via Forged customer.updated Webhook
Vulnerability Description
The SureCart plugin for WordPress is vulnerable to privilege escalation via account takeover in versions up to, and including, 4.2.3. This is due to the plugin not properly validating a user's identity prior to updating their details like email during customer profile synchronization from webhook events. This makes it possible for unauthenticated attackers to change linked user's email addresses, including administrators if the administrator account is linked to a SureCart customer record, and leverage that to reset the user's password and gain access to their account if the customer ID is known.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
忘记口令恢复机制弱
Vulnerability Title
surecart 授权问题漏洞
Vulnerability Description
surecart是surecart公司开源的一个电子商务管理平台。 surecart 4.2.3及之前版本存在授权问题漏洞,该漏洞源于在从Webhook事件同步客户资料时未正确验证用户身份,可能导致未经身份验证的攻击者更改关联用户的电子邮件地址,进而重置密码并接管账户。
CVSS Information
N/A
Vulnerability Type
N/A