脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media
脆弱性説明
The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files (bounded to an image and video allowlist) to the Media Library and create attachment posts, leading to media library pollution and disk space exhaustion.
CVSS情報
N/A
脆弱性タイプ
N/A
脆弱性タイトル
WordPress Customer Reviews for WooCommerce 任意文件上传漏洞
脆弱性説明
WordPress Customer Reviews for WooCommerce是WordPress基金会的一个为WooCommerce添加客户评价功能的插件。 WordPress Customer Reviews for WooCommerce 5.113.0之前版本存在任意文件上传漏洞,该漏洞源于未对媒体上传AJAX操作进行身份验证、权限或nonce检查,允许未经身份验证的用户上传媒体文件并创建附件帖子,导致媒体库污染和磁盘空间耗尽。
CVSS情報
N/A
脆弱性タイプ
N/A