WordPress WP Live Chat SupportÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-12

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12498£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ºÏÓÃÓÚWordPress WP Live Chat²å¼þ < 8.0.32 ¡£


·ì϶¸ÅÊö


WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHP˵»°¿ª·¢µÄ²©¿Íƽ̨£¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄ·þÎñÆ÷ÉϼÜÉèÓ×ÎÒ²©¿ÍÍøÕ¾ ¡£WP Live Chat SupportÊÇʹÓÃÔÚÆäÖеÄÒ»¸ö¼´Ê±Ì¸Ìì²å¼þ ¡£


WordPress WP Live Chat Support²å¼þ8.0.32¼°ÒÔǰ°æ±¾ÖгöÏÖÁËÑϳÁµÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶£¬¿É±»²»¾ß±¸ÓÐЧƾ֤µÄºÚ¿ÍÀûÓ㬽ӼûÕý±¾±»Ï޶ȵÄRESTAPI¶Ë¿Ú ¡£¾ßÌåÀ´Ëµ£¬Â¶³öµÄREST API¶Ëµã¿ÉÄÜÔÊÐíDZÔڵĹ¥»÷ÕßÌáÈ¡ÍøÕ¾ÖÐËùÓÐ̸Ìì»á»°µÄÆëÈ«¼Í¼£¬½«Îı¾×¢ÈëÔÚ½øÐеÄ̸Ìì»á»°£¬±à×ë×¢ÈëµÄÐÂÎÅ£¬²¢¡°ÇáÒ×ʵÏÖÔÚ½øÐеĻỰ¡±£¬ÌáÒéDoS¹¥»÷ ¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP ¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼а汾ÒÔ½¨¸´·ì϶£¬½«²å¼þ¸üе½×îа汾https://wordpress.org/plugins/wp-live-chat-support/ ¡£


²Î¿¼Á´½Ó


 https://blog.alertlogic.com/alert-logic-researchers-find-another-critical-vulnerability-in-wordpress-wp-live-chat-cve-2019-12498/