WordPress WP Live Chat SupportÉí·ÝÑéÖ¤ÈÆ¹ýÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-06-12

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12498£¬ £¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬ £¬£¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ÊÊÓÃÓÚWordPress WP Live Chat²å¼þ < 8.0.32¡£ ¡£¡£¡£¡£¡£¡£¡£


Îó²î¸ÅÊö


WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHPÓïÑÔ¿ª·¢µÄ²©¿Íƽ̨£¬ £¬£¬£¬£¬£¬£¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄЧÀÍÆ÷ÉϼÜÉèСÎÒ˽¼Ò²©¿ÍÍøÕ¾¡£ ¡£¡£¡£¡£¡£¡£¡£WP Live Chat SupportÊÇʹÓÃÔÚÆäÖеÄÒ»¸ö¼´Ê±Ì¸Ìì²å¼þ¡£ ¡£¡£¡£¡£¡£¡£¡£


WordPress WP Live Chat Support²å¼þ8.0.32¼°ÒÔǰ°æ±¾ÖзºÆðÁËÑÏÖØµÄÉí·ÝÑéÖ¤ÈÆ¹ýÎó²î£¬ £¬£¬£¬£¬£¬£¬¿É±»²»¾ß±¸ÓÐÓÃÆ¾Ö¤µÄºÚ¿ÍʹÓ㬠£¬£¬£¬£¬£¬£¬»á¼ûÔ­±¾±»ÏÞÖÆµÄRESTAPI¶Ë¿Ú¡£ ¡£¡£¡£¡£¡£¡£¡£ÏêϸÀ´Ëµ£¬ £¬£¬£¬£¬£¬£¬Ì»Â¶µÄREST API¶Ëµã¿ÉÄÜÔÊÐíDZÔڵĹ¥»÷ÕßÌáÈ¡ÍøÕ¾ÖÐËùÓÐ̸Ìì»á»°µÄÍêÕû¼Í¼£¬ £¬£¬£¬£¬£¬£¬½«Îı¾×¢ÈëÕýÔÚ¾ÙÐеÄ̸Ìì»á»°£¬ £¬£¬£¬£¬£¬£¬±à¼­×¢ÈëµÄÐÂÎÅ£¬ £¬£¬£¬£¬£¬£¬²¢¡°ËæÒâ¿¢ÊÂÕýÔÚ¾ÙÐеĻỰ¡±£¬ £¬£¬£¬£¬£¬£¬ÌᳫDoS¹¥»÷¡£ ¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£ ¡£¡£¡£¡£¡£¡£¡£


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Ð°汾ÒÔÐÞ¸´Îó²î£¬ £¬£¬£¬£¬£¬£¬½«²å¼þ¸üе½×îа汾https://wordpress.org/plugins/wp-live-chat-support/¡£ ¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


 https://blog.alertlogic.com/alert-logic-researchers-find-another-critical-vulnerability-in-wordpress-wp-live-chat-cve-2019-12498/