漏洞信息详情
WordPress Ultimate Member - User Profile & Membership Plugin 跨站脚本漏洞
漏洞简介
WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。Ultimate Member - User Profile & Membership Plugin是使用在其中的一个网站会员插件。
WordPress Ultimate Member - User Profile & Membership Plugin 2.0.28之前版本中的includes/core/um-actions-login.php页面存在跨站脚本漏洞。远程攻击者可借助‘Primary button Text’或‘Second button text’字段利用该漏洞注入任意web脚本或HTML。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://wordpress.org/plugins/ultimate-member/#developers
参考网址
来源:MISC
链接:https://wpvulndb.com/vulnerabilities/9615
来源:CONFIRM
链接:https://wordpress.org/plugins/ultimate-member/#developers
来源:MISC
链接:https://serhack.me/articles/ultimate-member-xss-security-issue
受影响实体
- Ultimatemember Ultimate_member:2.0.24:~~~Wordpress~~<!--2000-1-1-->
- Ultimatemember Ultimate_member:2.0.23:~~~Wordpress~~<!--2000-1-1-->
- Ultimatemember Ultimate_member:2.0.22:~~~Wordpress~~<!--2000-1-1-->
- Ultimatemember Ultimate_member:2.0.21:~~~Wordpress~~<!--2000-1-1-->
- Ultimatemember Ultimate_member:2.0.20:~~~Wordpress~~<!--2000-1-1-->
补丁
- WordPress Ultimate Member - User Profile & Membership Plugin 跨站脚本漏洞的修复措施<!--2018-10-10-->
还没有评论,来说两句吧...