{"id":2377,"date":"2015-04-20T18:07:04","date_gmt":"2015-04-20T18:07:04","guid":{"rendered":"http:\/\/musilda.cz\/?p=2377"},"modified":"2015-04-20T18:07:04","modified_gmt":"2015-04-20T18:07:04","slug":"xss-zranitelnost-ohrozujici-velke-mnozstvi-wordpress-pluginu","status":"publish","type":"post","link":"https:\/\/affinite.io\/cs\/xss-zranitelnost-ohrozujici-velke-mnozstvi-wordpress-pluginu\/","title":{"rendered":"XSS zranitelnost ohro\u017euj\u00edc\u00ed velk\u00e9 mno\u017estv\u00ed WordPRess plugin\u016f"},"content":{"rendered":"

Na blogu Sucuri dnes vy\u0161lo upozorn\u011bn\u00ed na zranitelnost, kter\u00e1 zas\u00e1hne doslova miliony u\u017eivatel\u016f po cel\u00e9m sv\u011bt\u011b. \u010casto pou\u017e\u00edvan\u00e9 funkce add_query_arg a remove_query_arg je pot\u0159eba p\u0159ed jejich pou\u017eit\u00edm escapovat, proto\u017ee samy o sob\u011b escapov\u00e1n\u00ed neobsahuj\u00ed.<\/p>\n

\u0158ada v\u00fdvoj\u00e1\u0159\u016f v\u0161ak spol\u00e9h\u00e1 na Codex, kde toto nen\u00ed jasn\u011b uvedeno. Probl\u00e9m byl detekov\u00e1n t\u00fdmek kolem pluginu WordPress SEO by Yoast a tento plugin ji\u017e m\u00e1 bezpe\u010dnostn\u00ed aktualizaci.<\/p>\n

Seznam plugin\u016f, kter\u00fdch se probl\u00e9m t\u00fdk\u00e1:<\/p>\n