WordPress WP Live Chat SupportÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-12

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12498£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚWordPress WP Live Chat²å¼þ < 8.0.32¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨£¬£¬£¬£¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£¡£¡£WP Live Chat SupportÊÇʹÓÃÔÚÆäÖеÄÒ»¸ö¼´Ê±Ì¸Ìì²å¼þ¡£¡£¡£¡£¡£


WordPress WP Live Chat Support²å¼þ8.0.32¼°ÒÔǰ°æ±¾ÖзºÆðÁËÑÏÖØµÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬¿É±»²»¾ß±¸ÓÐÓÃÆ¾Ö¤µÄºÚ¿ÍʹÓ㬣¬£¬£¬»á¼ûÔ­±¾±»ÏÞÖÆµÄRESTAPI¶Ë¿Ú¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬Ì»Â¶µÄREST API¶Ëµã¿ÉÄÜÔÊÐíDZÔڵĹ¥»÷ÕßÌáÈ¡ÍøÕ¾ÖÐËùÓÐ̸Ìì»á»°µÄÍêÕû¼Í¼£¬£¬£¬£¬½«Îı¾×¢ÈëÕýÔÚ¾ÙÐеÄ̸Ìì»á»°£¬£¬£¬£¬±à¼­×¢ÈëµÄÐÂÎÅ£¬£¬£¬£¬²¢¡°ËæÒâ¿¢ÊÂÕýÔÚ¾ÙÐеĻỰ¡±£¬£¬£¬£¬ÌᳫDoS¹¥»÷¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬½«²å¼þ¸üе½×îа汾https://wordpress.org/plugins/wp-live-chat-support/¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


 https://blog.alertlogic.com/alert-logic-researchers-find-another-critical-vulnerability-in-wordpress-wp-live-chat-cve-2019-12498/