---
title: WebPros国际的WHMCS发现严重安全漏洞
url: https://www.dataloco.com/zh/webproswhmcs
published: 2026-09-18T01:22:33+00:00
language: zh
section: 安全
source: https://www.security-next.com/190306
organizations: WebPros, WHMCS, 2CheckOut, HackerOne
publisher: Dataloco
---

# WebPros国际的WHMCS发现严重安全漏洞

WebPros International提供的面向托管服务提供商和云服务提供商的账单管理软件“WHMCS”被发现存在严重安全漏洞。该公司于当地时间2026年9月3日发布了安全咨询，明确了两处影响不同版本的漏洞。两者均通过该公司安全程序报告。

“CVE-2026-67399”是由于不可信数据的反序列化引起的漏洞，在特定条件下可在无需认证的情况下在服务器上执行任意代码，可能导致该产品的安装环境和相关数据受到侵害。

另外，支付网关“2CheckOut”中发现的“CVE-2026-67398”漏洞是由于缺乏授权处理造成的，无需认证即可获取客户的姓名、地址、邮箱和电话号码等个人信息。

HackerOne为CVE编号提供的“CVE-2026-67399”在通用漏洞评分系统“CVSSv4.0”中的基础分数为“9.3”，被评为“关键（Critical）”级别。“CVE-2026-67398”的CVSS基础值为“8.2”，被评为“高（High）”级别。

WebPros已经发布了修复这些漏洞的“WHMCS 9.0.8”和“8.13.7”版本，并呼吁用户进行更新。此外，针对“CVE-2026-67398”，该公司提供了禁用“2CheckOut”模块的临时解决方案。

## This story in other languages

- [Türkçe](https://www.dataloco.com/tr/whmcs-faturalama-yaziliminda-ciddi-guvenlik-aciklari-tespit-edildi)
- [עברית](https://www.dataloco.com/he/whmcs)
- [Deutsch](https://www.dataloco.com/de/schwere-sicherheitslucken-in-der-abrechnungssoftware-whmcs-entdeckt)
- [English](https://www.dataloco.com/en/webpros-releases-urgent-patches-for-critical-whmcs-flaws)
- [Italiano](https://www.dataloco.com/it/gravi-vulnerabilita-scoperte-nel-software-di-fatturazione-whmcs)
- [Português (Brasil)](https://www.dataloco.com/pt-br/webpros-identifica-vulnerabilidades-criticas-no-whmcs)
- [한국어](https://www.dataloco.com/ko/whmcs)
- [ไทย](https://www.dataloco.com/th/whmcs-webpros-international)
