WordPress WP Live Chat SupportÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-12

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12498£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚWordPress WP Live Chat²å¼þ < 8.0.32¡£¡£¡£


Îó²î¸ÅÊö


WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨£¬£¬£¬£¬£¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£¡£¡£WP Live Chat SupportÊÇʹÓÃÔÚÆäÖеÄÒ»¸ö¼´Ê±Ì¸Ìì²å¼þ¡£¡£¡£


WordPress WP Live Chat Support²å¼þ8.0.32¼°ÒÔǰ°æ±¾ÖзºÆðÁËÑÏÖØµÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬£¬£¬£¬£¬¿É±»²»¾ß±¸ÓÐÓÃÆ¾Ö¤µÄºÚ¿ÍʹÓ㬣¬£¬£¬£¬»á¼ûÔ­±¾±»ÏÞÖÆµÄRESTAPI¶Ë¿Ú¡£¡£¡£ÏêϸÀ´Ëµ£¬£¬£¬£¬£¬Ì»Â¶µÄREST API¶Ëµã¿ÉÄÜÔÊÐíDZÔڵĹ¥»÷ÕßÌáÈ¡ÍøÕ¾ÖÐËùÓÐ̸Ìì»á»°µÄÍêÕû¼Í¼£¬£¬£¬£¬£¬½«Îı¾×¢ÈëÕýÔÚ¾ÙÐеÄ̸Ìì»á»°£¬£¬£¬£¬£¬±à¼­×¢ÈëµÄÐÂÎÅ£¬£¬£¬£¬£¬²¢¡°ËæÒâ¿¢ÊÂÕýÔÚ¾ÙÐеĻỰ¡±£¬£¬£¬£¬£¬ÌᳫDoS¹¥»÷¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾ÒÔÐÞ¸´Îó²î£¬£¬£¬£¬£¬½«²å¼þ¸üе½×îа汾https://wordpress.org/plugins/wp-live-chat-support/¡£¡£¡£


²Î¿¼Á´½Ó


 https://blog.alertlogic.com/alert-logic-researchers-find-another-critical-vulnerability-in-wordpress-wp-live-chat-cve-2019-12498/