### CVE-2023-27160 - Cross Site Request Forgery (CSRF) #### Description forem up to v2022.11.11 was discovered to contain a Cross Site Request Forgery (CSRF) via the component `/articles, /articles/{i…
### Vulnerability Key Information - **Source**: `responsive-lightbox/trunk/includes/class-remote-library.php` - **Last Change**: Revision 464562 by dfactory, checked in 7 days ago - **File Size**: 28.…
### 关键漏洞信息 #### 1. 错误处理和验证 - **Code Changes in `includes/class-frontend.php`** - The old code uses `esc_html` to escape the URL, which is not sufficient for sanitizing URLs. This could lead to potenti…