CVE-2017-16815
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More に報告された脆弱性
概要
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplicator/installer/build/view.step2.php) are not filtered correctly.
影響を受けるバージョン
- 1.2.28以上 〜 1.2.28以下
対処方法
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More を 1.2.30 以降に更新してください。これで本脆弱性は解消します。
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する参照
- https://packetstormsecurity.com/files/144914/WordPress-Duplicator-Migration-1.2.28-Cross-Site-Scripting.html
- https://snapcreek.com/duplicator/docs/changelog
- https://packetstormsecurity.com/files/144914/WordPress-Duplicator-Migration-1.2.28-Cross-Site-Scripting.html
- https://snapcreek.com/duplicator/docs/changelog