漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking
Vulnerability Description
The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowing unauthenticated attackers to silently redirect the shipping destination of any pending or processing order on the site.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ilabs InPost PL 权限许可和访问控制问题漏洞
Vulnerability Description
ilabs InPost PL是波兰ilabs公司的一款专为使用 WooCommerce 平台的中小企业打造的官方物流集成插件。 ilabs InPost PL 1.9.1之前版本存在权限许可和访问控制问题漏洞,该漏洞源于未验证请求是否来自合法买家,可能导致未经验证的攻击者静默重定向网站上任何待处理或处理中订单的送货地址。
CVSS Information
N/A
Vulnerability Type
N/A