【資安通報】
風險等級(滿分為10分): 6.4
受影響版本: <= 3.10.4
簡述:
由於未能適當過濾輸入並進行輸出轉義,因此容易受到存儲型跨網站指令碼攻擊,透過文章、頁面標題的 HTML 標籤進行攻擊。這使得已認證的攻擊者(具有投稿者等級的訪問權限或更高權限)能夠在頁面中插入任意的 Web 指令碼,當使用者訪問被注入的頁面時,該指令碼將被執行。
參考資料:
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/happy-elementor-addons/happy-addons-for-elementor-3104-authenticated-contributor-stored-cross-site-scripting-via-post-title-html-tag
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/happy-elementor-addons/happy-addons-for-elementor-3104-incorrect-authorization-to-information-exposure
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/happy-elementor-addons/happy-addons-for-elementor-3104-authenticated-contributor-stored-cross-site-scripting-via-calendy
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/happy-elementor-addons/happy-addons-for-elementor-3104-authenticated-contributor-dom-based-stored-cross-site-scripting-via-title-tag
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/happy-elementor-addons/happy-addons-for-elementor-3104-authenticated-contributor-stored-cross-site-scripting-via-page-title-html-tag
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/happy-elementor-addons/happy-addons-for-elementor-3103-authenticated-contributor-stored-cross-site-scripting-via-photo-stack-widget
#大邵報資安
#WordPress