漏洞标题
SupportCandy – Helpdesk & 客户支持票务系统 <= 3.3.0 版本存在不安全直接对象引用漏洞
漏洞描述信息
WordPress插件SupportCandy – Helpdesk & Customer Support Ticket System 在所有版本中(包括3.3.0版本)存在不安全直接对象引用漏洞。该漏洞是由于在文件上传过程中缺少对用户可控密钥的验证,导致经过身份验证的攻击者可以下载不属于他们的支持票据附件。如果管理员允许游客创建票据,未经过身份验证的攻击者也可以利用此漏洞。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
漏洞类别
通过用户控制密钥绕过授权机制
漏洞标题
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference
漏洞描述信息
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due to missing validation on a user controlled key. This makes it possible for authenticated attackers to download attachments for support tickets that don't belong to them. If an admin enables tickets for guests, this can be exploited by unauthenticated attackers.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
漏洞类别
授权机制不恰当