CVE-2022-2551
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More に報告された脆弱性
概要
The Duplicator WordPress Plugin is vulnerable to Unauthenticated Backup Download in versions up to, and including, 1.4.7 via the 'is_daws' parameter due to the fact that the source code of the response contains the randomized filename related to the back-up file that also exists in the same directory. This makes it possible for an unauthenticated attacker to download a full site backup which may contain sensitive information. This requires that the installer script has been run at least once by a site owner/administrator.
影響を受けるバージョン
- 1.4.7 以下
対処方法
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More を 1.4.7.1 以降に更新してください。これで本脆弱性は解消します。
Duplicator – Backups & Migration Plugin – Cloud Backups, Scheduled Backups, & More の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する