WordPress WP Live Chat SupportÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-06-12

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12498 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ºÏÓÃÓÚWordPress WP Live Chat²å¼þ < 8.0.32¡£


·ì϶¸ÅÊö


WordPressÊÇWordPressÈí¼þ»ù½ð»áµÄÒ»Ì×ʹÓÃPHP˵»°¿ª·¢µÄ²©¿Íƽ̨ £¬¸Ãƽ̨֧³ÖÔÚPHPºÍMySQLµÄ·þÎñÆ÷ÉϼÜÉèÓ×ÎÒ²©¿ÍÍøÕ¾¡£WP Live Chat SupportÊÇʹÓÃÔÚÆäÖеÄÒ»¸ö¼´Ê±Ì¸Ìì²å¼þ¡£


WordPress WP Live Chat Support²å¼þ8.0.32¼°ÒÔǰ°æ±¾ÖгöÏÖÁËÑϳÁµÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ £¬¿É±»²»¾ß±¸ÓÐЧƾ֤µÄºÚ¿ÍÀûÓà £¬½Ó¼ûÕý±¾±»Ï޶ȵÄRESTAPI¶Ë¿Ú¡£¾ßÌåÀ´Ëµ £¬Â¶³öµÄREST API¶Ëµã¿ÉÄÜÔÊÐíDZÔڵĹ¥»÷ÕßÌáÈ¡ÍøÕ¾ÖÐËùÓÐ̸Ìì»á»°µÄÆëÈ«¼Í¼ £¬½«Îı¾×¢ÈëÔÚ½øÐеÄ̸Ìì»á»° £¬±à×ë×¢ÈëµÄÐÂÎÅ £¬²¢¡°ÇáÒ×ʵÏÖÔÚ½øÐеĻỰ¡± £¬ÌáÒéDoS¹¥»÷¡£


·ì϶ÑéÖ¤


ÔÝÎÞPOC/EXP¡£


½¨¸´½¨Òé


Ŀǰ³§ÉÌÒѰ䲼а汾ÒÔ½¨¸´·ì϶ £¬½«²å¼þ¸üе½×îа汾https://wordpress.org/plugins/wp-live-chat-support/¡£


²Î¿¼Á´½Ó


 https://blog.alertlogic.com/alert-logic-researchers-find-another-critical-vulnerability-in-wordpress-wp-live-chat-cve-2019-12498/