WordPress 的 LiteSpeed Cache 插件存在反射型跨站脚本(Reflected Cross-Site Scripting)漏洞,影响 7.9 及之前所有版本。该漏洞由 参数缺乏足够的输入净化和输出转义所导致。 未认证的 attackers 若能让用户点击链接或执行特定操作,即可在页面中注入任意 Web 脚本。利用该漏洞时,攻击者需要在 GET 查询字符串中提供一个有效签名的 值,同时通过 POST 请求体提交一个由攻击者控制的 载荷,并依赖 PHP 中 默认的合并顺序(POST 优先于 GET)
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| litespeedtech | LiteSpeed Cache | 0 ~ 7.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet