CVE-2022-1054: WordPress RSVP and Event Management <2.7.8 - Missing Authorization

CVE-2022-1054: WordPress RSVP and Event Management <2.7.8 - Missing Authorization-渗透云记 - 专注于网络安全与技术分享
CVE-2022-1054: WordPress RSVP and Event Management <2.7.8 - Missing Authorization
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-1054: WordPress RSVP and Event Management <2.7.8 – Missing Authorization

漏洞描述

WordPress RSVP and Event Management plugin before 2.7.8 is susceptible to missing authorization. The plugin does not have any authorization checks when exporting its entries, and the export function is hooked to the init action. An attacker can potentially retrieve sensitive information such as first name, last name, and email address of users registered for events,

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享