CVE-2020-13700: WordPress acf-to-rest-api <=3.1.0 - Insecure Direct Object Reference

CVE-2020-13700: WordPress acf-to-rest-api <=3.1.0 - Insecure Direct Object Reference-渗透云记 - 专注于网络安全与技术分享
CVE-2020-13700: WordPress acf-to-rest-api <=3.1.0 - Insecure Direct Object Reference
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-13700: WordPress acf-to-rest-api <=3.1.0 – Insecure Direct Object Reference

漏洞描述

WordPress acf-to-rest-ap through 3.1.0 allows an insecure direct object reference via permalinks manipulation, as demonstrated by a wp-json/acf/v3/options/ request that can read sensitive information in the wp_options table such as the login and pass values.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享