脆弱性情報
高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
脆弱性タイトル
WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification
脆弱性説明
The WP Business Intelligence Lite plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify stored SQL queries, which can lead to privilege escalation via arbitrary SQL execution when the modified query is viewed by an administrator.
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
脆弱性タイプ
授权机制缺失
脆弱性タイトル
WordPress WP Business Intelligence Lite 授权问题漏洞
脆弱性説明
WordPress WP Business Intelligence Lite是WordPress基金会的一款WordPress商业智能精简插件。 WordPress WP Business Intelligence Lite 3.2.0及之前版本存在授权问题漏洞,该漏洞源于未正确验证用户授权,可能导致已认证的攻击者修改存储的SQL查询,当管理员查看修改后的查询时,通过任意SQL执行导致权限提升。
CVSS情報
N/A
脆弱性タイプ
N/A