VPS_XHQ Telegram 641
WP Litespeed Cache 插件存在严重权限提升漏洞

研究人员在著名的 LiteSpeed Cache WordPress 插件中发现了一个未经身份验证的权限提升漏洞 ( CVE-2024-28000 ),该漏洞存在于 LiteSpeed Cache 6.3.0.1 及更高版本中,是由弱哈希校验引起的。

成功利用该漏洞可使任何未经身份验证的访问者获得管理员级别的访问权限,通过安装恶意插件、更改关键设置、将流量重定向到恶意网站、向访问者分发恶意软件或窃取用户数据,攻击者可以完全接管网站。由于该插件安装量高达500万,预计黑客能够通过创建恶意管理员帐户来控制上百万个网站。

LiteSpeed 团队已在 LiteSpeed Cache 6.4 版中修复了该漏洞。运行该插件的网站应当立即更新到最新版本。

[消息等级 Level C2 · 简要]



tgoop.com/vps_xhq/641
Create:
Last Update:

WP Litespeed Cache 插件存在严重权限提升漏洞

研究人员在著名的 LiteSpeed Cache WordPress 插件中发现了一个未经身份验证的权限提升漏洞 ( CVE-2024-28000 ),该漏洞存在于 LiteSpeed Cache 6.3.0.1 及更高版本中,是由弱哈希校验引起的。

成功利用该漏洞可使任何未经身份验证的访问者获得管理员级别的访问权限,通过安装恶意插件、更改关键设置、将流量重定向到恶意网站、向访问者分发恶意软件或窃取用户数据,攻击者可以完全接管网站。由于该插件安装量高达500万,预计黑客能够通过创建恶意管理员帐户来控制上百万个网站。

LiteSpeed 团队已在 LiteSpeed Cache 6.4 版中修复了该漏洞。运行该插件的网站应当立即更新到最新版本。

[消息等级 Level C2 · 简要]

BY VPS信号旗播报


Share with your friend now:
tgoop.com/vps_xhq/641

View MORE
Open in Telegram


Telegram News

Date: |

Commenting about the court's concerns about the spread of false information related to the elections, Minister Fachin noted Brazil is "facing circumstances that could put Brazil's democracy at risk." During the meeting, the information technology secretary at the TSE, Julio Valente, put forward a list of requests the court believes will disinformation. Those being doxxed include outgoing Chief Executive Carrie Lam Cheng Yuet-ngor, Chung and police assistant commissioner Joe Chan Tung, who heads police's cyber security and technology crime bureau. How to Create a Private or Public Channel on Telegram? “[The defendant] could not shift his criminal liability,” Hui said. Choose quality over quantity. Remember that one high-quality post is better than five short publications of questionable value.
from us


Telegram VPS信号旗播报
FROM American