漏洞标题
Safe Ai Malware Protection for WP 1.0.17及之前版本存在未授权数据库导出漏洞
漏洞描述信息
WordPress插件Safe Ai Malware Protection for WP在所有版本(包括1.0.17版本)中,由于export_db()函数缺少能力检查,存在未授权访问漏洞。这使得未认证的攻击者能够获取站点数据库的完整备份。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
漏洞类别
授权机制缺失
漏洞标题
Safe Ai Malware Protection for WP <= 1.0.17 - Missing Authorization to Unauthenticated Database Export
漏洞描述信息
The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db() function in all versions up to, and including, 1.0.17. This makes it possible for unauthenticated attackers to retrieve a complete dump of the site's database.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
授权机制缺失