kb: expand authorized lab coverage and intel automation
这个提交包含在:
@@ -0,0 +1,16 @@
|
||||
# ecommerce
|
||||
|
||||
> 自动生成系统分组索引
|
||||
|
||||
- 系统数量: `9`
|
||||
- 允许范围: `lab-local`, `lab-public`, `authorized-third-party`
|
||||
|
||||
- [Adobe Commerce](/Users/x/websafe/07-framework-security/ecommerce/adobe-commerce/README.md)
|
||||
- [Magento Open Source](/Users/x/websafe/07-framework-security/ecommerce/magento-open-source/README.md)
|
||||
- [Medusa](/Users/x/websafe/07-framework-security/ecommerce/medusa/README.md)
|
||||
- [OpenCart](/Users/x/websafe/07-framework-security/ecommerce/opencart/README.md)
|
||||
- [OpenMage / Mage-OS](/Users/x/websafe/07-framework-security/ecommerce/openmage/README.md)
|
||||
- [PrestaShop](/Users/x/websafe/07-framework-security/ecommerce/prestashop/README.md)
|
||||
- [Saleor](/Users/x/websafe/07-framework-security/ecommerce/saleor/README.md)
|
||||
- [Shopware](/Users/x/websafe/07-framework-security/ecommerce/shopware/README.md)
|
||||
- [WooCommerce](/Users/x/websafe/07-framework-security/ecommerce/woocommerce/README.md)
|
||||
@@ -0,0 +1,31 @@
|
||||
# Adobe Commerce
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
|
||||
|
||||
- 系统 ID: `adobe-commerce`
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖策略: `history-full`
|
||||
- 总案例数: `0`
|
||||
- 近 30 天新增/更新: `0`
|
||||
- 重点 Markdown 案例数: `0`
|
||||
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
|
||||
|
||||
## 目标约束
|
||||
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but ownership or authorization is required`
|
||||
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
## 来源
|
||||
|
||||
- `official` [Adobe Security Bulletins](https://helpx.adobe.com/security/products/magento.html) (mode=core)
|
||||
- `official` [NVD Adobe Commerce](https://nvd.nist.gov/vuln/search) (keyword=Adobe Commerce; mode=core)
|
||||
- `ecosystem-authority` [Sansec Research](https://sansec.io/research) (mode=extension)
|
||||
|
||||
## 案例列表
|
||||
|
||||
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|
||||
|------|--------|------|------------|----------|--------|
|
||||
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |
|
||||
@@ -0,0 +1,16 @@
|
||||
# Adobe Commerce
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
|
||||
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖层级: `history-full`
|
||||
- Advisory 模式: core, extension
|
||||
- 输出目录: `07-framework-security/ecommerce/adobe-commerce`
|
||||
- 修复主题: authz-server-side-recheck, file-upload-validation, xss-output-encoding, plugin-extension-trust-policy
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but only for owned or authorized targets`
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/ecommerce/adobe-commerce/INDEX.md)
|
||||
- Registry 统计: [adobe-commerce.json](/Users/x/websafe/08-threat-intel/registry/systems/adobe-commerce.json)
|
||||
@@ -0,0 +1,31 @@
|
||||
# Magento Open Source
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
|
||||
|
||||
- 系统 ID: `magento-open-source`
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖策略: `history-full`
|
||||
- 总案例数: `0`
|
||||
- 近 30 天新增/更新: `0`
|
||||
- 重点 Markdown 案例数: `0`
|
||||
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
|
||||
|
||||
## 目标约束
|
||||
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but ownership or authorization is required`
|
||||
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
## 来源
|
||||
|
||||
- `official` [Magento GitHub Advisories](https://github.com/magento/magento2/security/advisories) (mode=core)
|
||||
- `official` [NVD Magento](https://nvd.nist.gov/vuln/search) (keyword=Magento; mode=core)
|
||||
- `ecosystem-authority` [Sansec Research](https://sansec.io/research) (mode=extension)
|
||||
|
||||
## 案例列表
|
||||
|
||||
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|
||||
|------|--------|------|------------|----------|--------|
|
||||
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |
|
||||
@@ -0,0 +1,16 @@
|
||||
# Magento Open Source
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
|
||||
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖层级: `history-full`
|
||||
- Advisory 模式: core, extension
|
||||
- 输出目录: `07-framework-security/ecommerce/magento-open-source`
|
||||
- 修复主题: authz-server-side-recheck, file-upload-validation, plugin-extension-trust-policy
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but only for owned or authorized targets`
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/ecommerce/magento-open-source/INDEX.md)
|
||||
- Registry 统计: [magento-open-source.json](/Users/x/websafe/08-threat-intel/registry/systems/magento-open-source.json)
|
||||
@@ -0,0 +1,30 @@
|
||||
# Medusa
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
|
||||
|
||||
- 系统 ID: `medusa`
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖策略: `rolling-24m`
|
||||
- 总案例数: `0`
|
||||
- 近 30 天新增/更新: `0`
|
||||
- 重点 Markdown 案例数: `0`
|
||||
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
|
||||
|
||||
## 目标约束
|
||||
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but ownership or authorization is required`
|
||||
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
## 来源
|
||||
|
||||
- `official` [GitHub Medusa Advisories](https://github.com/medusajs/medusa/security/advisories) (mode=core)
|
||||
- `official` [OSV Medusa](https://osv.dev/) (mode=core)
|
||||
|
||||
## 案例列表
|
||||
|
||||
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|
||||
|------|--------|------|------------|----------|--------|
|
||||
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |
|
||||
@@ -0,0 +1,16 @@
|
||||
# Medusa
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
|
||||
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖层级: `rolling-24m`
|
||||
- Advisory 模式: core, extension
|
||||
- 输出目录: `07-framework-security/ecommerce/medusa`
|
||||
- 修复主题: authz-server-side-recheck, token-cookie-storage
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but only for owned or authorized targets`
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/ecommerce/medusa/INDEX.md)
|
||||
- Registry 统计: [medusa.json](/Users/x/websafe/08-threat-intel/registry/systems/medusa.json)
|
||||
@@ -0,0 +1,30 @@
|
||||
# OpenCart
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
|
||||
|
||||
- 系统 ID: `opencart`
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖策略: `history-full`
|
||||
- 总案例数: `0`
|
||||
- 近 30 天新增/更新: `0`
|
||||
- 重点 Markdown 案例数: `0`
|
||||
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
|
||||
|
||||
## 目标约束
|
||||
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but ownership or authorization is required`
|
||||
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
## 来源
|
||||
|
||||
- `official` [OpenCart Releases](https://github.com/opencart/opencart/releases) (mode=core)
|
||||
- `official` [NVD OpenCart](https://nvd.nist.gov/vuln/search) (keyword=OpenCart; mode=core)
|
||||
|
||||
## 案例列表
|
||||
|
||||
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|
||||
|------|--------|------|------------|----------|--------|
|
||||
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |
|
||||
@@ -0,0 +1,16 @@
|
||||
# OpenCart
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
|
||||
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖层级: `history-full`
|
||||
- Advisory 模式: core, extension
|
||||
- 输出目录: `07-framework-security/ecommerce/opencart`
|
||||
- 修复主题: authz-server-side-recheck, plugin-extension-trust-policy, file-upload-validation
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but only for owned or authorized targets`
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/ecommerce/opencart/INDEX.md)
|
||||
- Registry 统计: [opencart.json](/Users/x/websafe/08-threat-intel/registry/systems/opencart.json)
|
||||
@@ -0,0 +1,30 @@
|
||||
# OpenMage / Mage-OS
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
|
||||
|
||||
- 系统 ID: `openmage`
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖策略: `rolling-24m`
|
||||
- 总案例数: `0`
|
||||
- 近 30 天新增/更新: `0`
|
||||
- 重点 Markdown 案例数: `0`
|
||||
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
|
||||
|
||||
## 目标约束
|
||||
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but ownership or authorization is required`
|
||||
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
## 来源
|
||||
|
||||
- `official` [OpenMage GitHub Advisories](https://github.com/OpenMage/magento-lts/security/advisories) (mode=core)
|
||||
- `official` [NVD OpenMage](https://nvd.nist.gov/vuln/search) (keyword=OpenMage; mode=core)
|
||||
|
||||
## 案例列表
|
||||
|
||||
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|
||||
|------|--------|------|------------|----------|--------|
|
||||
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |
|
||||
@@ -0,0 +1,16 @@
|
||||
# OpenMage / Mage-OS
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
|
||||
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖层级: `rolling-24m`
|
||||
- Advisory 模式: core, extension
|
||||
- 输出目录: `07-framework-security/ecommerce/openmage`
|
||||
- 修复主题: authz-server-side-recheck, plugin-extension-trust-policy
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but only for owned or authorized targets`
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/ecommerce/openmage/INDEX.md)
|
||||
- Registry 统计: [openmage.json](/Users/x/websafe/08-threat-intel/registry/systems/openmage.json)
|
||||
@@ -0,0 +1,31 @@
|
||||
# PrestaShop
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
|
||||
|
||||
- 系统 ID: `prestashop`
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖策略: `history-full`
|
||||
- 总案例数: `0`
|
||||
- 近 30 天新增/更新: `0`
|
||||
- 重点 Markdown 案例数: `0`
|
||||
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
|
||||
|
||||
## 目标约束
|
||||
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but ownership or authorization is required`
|
||||
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
## 来源
|
||||
|
||||
- `official` [PrestaShop Security Page](https://build.prestashop-project.org/news/) (mode=core)
|
||||
- `official` [GitHub PrestaShop Advisories](https://github.com/PrestaShop/PrestaShop/security/advisories) (mode=core)
|
||||
- `ecosystem-authority` [Friends Of Presta Security](https://security.friendsofpresta.org/) (mode=module)
|
||||
|
||||
## 案例列表
|
||||
|
||||
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|
||||
|------|--------|------|------------|----------|--------|
|
||||
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |
|
||||
@@ -0,0 +1,16 @@
|
||||
# PrestaShop
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
|
||||
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖层级: `history-full`
|
||||
- Advisory 模式: core, module
|
||||
- 输出目录: `07-framework-security/ecommerce/prestashop`
|
||||
- 修复主题: plugin-extension-trust-policy, authz-server-side-recheck, file-upload-validation
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but only for owned or authorized targets`
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/ecommerce/prestashop/INDEX.md)
|
||||
- Registry 统计: [prestashop.json](/Users/x/websafe/08-threat-intel/registry/systems/prestashop.json)
|
||||
@@ -0,0 +1,30 @@
|
||||
# Saleor
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
|
||||
|
||||
- 系统 ID: `saleor`
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖策略: `rolling-24m`
|
||||
- 总案例数: `0`
|
||||
- 近 30 天新增/更新: `0`
|
||||
- 重点 Markdown 案例数: `0`
|
||||
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
|
||||
|
||||
## 目标约束
|
||||
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but ownership or authorization is required`
|
||||
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
## 来源
|
||||
|
||||
- `official` [GitHub Saleor Advisories](https://github.com/saleor/saleor/security/advisories) (mode=core)
|
||||
- `official` [NVD Saleor](https://nvd.nist.gov/vuln/search) (keyword=Saleor; mode=core)
|
||||
|
||||
## 案例列表
|
||||
|
||||
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|
||||
|------|--------|------|------------|----------|--------|
|
||||
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |
|
||||
@@ -0,0 +1,16 @@
|
||||
# Saleor
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
|
||||
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖层级: `rolling-24m`
|
||||
- Advisory 模式: core, extension
|
||||
- 输出目录: `07-framework-security/ecommerce/saleor`
|
||||
- 修复主题: authz-server-side-recheck, token-cookie-storage
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but only for owned or authorized targets`
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/ecommerce/saleor/INDEX.md)
|
||||
- Registry 统计: [saleor.json](/Users/x/websafe/08-threat-intel/registry/systems/saleor.json)
|
||||
@@ -0,0 +1,30 @@
|
||||
# Shopware
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
|
||||
|
||||
- 系统 ID: `shopware`
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖策略: `history-full`
|
||||
- 总案例数: `0`
|
||||
- 近 30 天新增/更新: `0`
|
||||
- 重点 Markdown 案例数: `0`
|
||||
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
|
||||
|
||||
## 目标约束
|
||||
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but ownership or authorization is required`
|
||||
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
## 来源
|
||||
|
||||
- `official` [Shopware Security Advisories](https://github.com/shopware/shopware/security/advisories) (mode=core)
|
||||
- `official` [NVD Shopware](https://nvd.nist.gov/vuln/search) (keyword=Shopware; mode=core)
|
||||
|
||||
## 案例列表
|
||||
|
||||
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|
||||
|------|--------|------|------------|----------|--------|
|
||||
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |
|
||||
@@ -0,0 +1,16 @@
|
||||
# Shopware
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
|
||||
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖层级: `history-full`
|
||||
- Advisory 模式: core, extension
|
||||
- 输出目录: `07-framework-security/ecommerce/shopware`
|
||||
- 修复主题: authz-server-side-recheck, plugin-extension-trust-policy, file-upload-validation
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but only for owned or authorized targets`
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/ecommerce/shopware/INDEX.md)
|
||||
- Registry 统计: [shopware.json](/Users/x/websafe/08-threat-intel/registry/systems/shopware.json)
|
||||
@@ -0,0 +1,32 @@
|
||||
# WooCommerce
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY` | 自动生成索引
|
||||
|
||||
- 系统 ID: `woocommerce`
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖策略: `history-full`
|
||||
- 总案例数: `0`
|
||||
- 近 30 天新增/更新: `0`
|
||||
- 重点 Markdown 案例数: `0`
|
||||
- 最近渲染时间: `2026-03-17T04:37:52+00:00`
|
||||
|
||||
## 目标约束
|
||||
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but ownership or authorization is required`
|
||||
- 授权前提: 资产归属可证明,或已取得书面/明确授权。
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
## 来源
|
||||
|
||||
- `official` [Woo Developer Advisories](https://developer.woocommerce.com/) (mode=core)
|
||||
- `official` [GitHub WooCommerce Advisories](https://github.com/woocommerce/woocommerce/security/advisories) (mode=core)
|
||||
- `ecosystem-authority` [Patchstack Database](https://patchstack.com/database/) (mode=extension)
|
||||
- `ecosystem-authority` [Wordfence Vulnerability Database](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/) (mode=extension)
|
||||
|
||||
## 案例列表
|
||||
|
||||
| 标题 | 严重度 | 状态 | 来源置信度 | 更新时间 | 案例页 |
|
||||
|------|--------|------|------------|----------|--------|
|
||||
| No advisories yet | `n/a` | `empty` | `n/a` | `n/a` | - |
|
||||
@@ -0,0 +1,16 @@
|
||||
# WooCommerce
|
||||
|
||||
> `LAB ONLY` | `AUTHORIZED TARGETS ONLY`
|
||||
|
||||
- 分类: `ecommerce`
|
||||
- 覆盖层级: `history-full`
|
||||
- Advisory 模式: core, extension
|
||||
- 输出目录: `07-framework-security/ecommerce/woocommerce`
|
||||
- 修复主题: plugin-extension-trust-policy, xss-output-encoding, authz-server-side-recheck
|
||||
- 适用目标类型: `lab-local, lab-public, authorized-third-party`
|
||||
- 是否允许公网验证: `yes, but only for owned or authorized targets`
|
||||
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
|
||||
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
|
||||
|
||||
- 自动索引: [INDEX.md](/Users/x/websafe/07-framework-security/ecommerce/woocommerce/INDEX.md)
|
||||
- Registry 统计: [woocommerce.json](/Users/x/websafe/08-threat-intel/registry/systems/woocommerce.json)
|
||||
在新工单中引用
屏蔽一个用户