CVE-2021-24610
TranslatePress – Translate Multilingual sites with AI Translation に報告された脆弱性
概要
The TranslatePress WordPress plugin before 2.0.9 does not implement a proper sanitisation on the translated strings. The 'trp_sanitize_string' function only removes script tag with a regex, still allowing other HTML tags and attributes to execute javascript, which could lead to authenticated Stored Cross-Site Scripting issues.
影響を受けるバージョン
- 2.0.9 未満
対処方法
TranslatePress – Translate Multilingual sites with AI Translation を 2.0.9 以降に更新してください。これで本脆弱性は解消します。
この脆弱性は実証コードが公開されています。攻撃に利用されやすい状態のため、優先して対応してください。
TranslatePress – Translate Multilingual sites with AI Translation の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する参照
- http://packetstormsecurity.com/files/164306/WordPress-TranslatePress-2.0.8-Cross-Site-Scripting.html
- https://wpscan.com/vulnerability/b87fcc2f-c2eb-4e23-9757-d1c590f26d3f
- http://packetstormsecurity.com/files/164306/WordPress-TranslatePress-2.0.8-Cross-Site-Scripting.html
- https://wpscan.com/vulnerability/b87fcc2f-c2eb-4e23-9757-d1c590f26d3f