漏洞描述
Asgaros Forum for WordPress versions prior to 3.2.0 is vulnerable to unauthenticated SQL injection through the asgarosforum_unread_exclude cookie. The cookie is JSON-decoded and its object keys are imploded into a NOT IN() clause without sanitisation. The vulnerable query only runs while rendering the forum page, so the payload must be sent there rather than to the site root.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。