CVE-2022-4140: WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access

CVE-2022-4140: WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access-渗透云记 - 专注于网络安全与技术分享
CVE-2022-4140: WordPress Welcart e-Commerce <2.8.5 - Arbitrary File Access
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-4140: WordPress Welcart e-Commerce <2.8.5 – Arbitrary File Access

漏洞描述

WordPress Welcart e-Commerce plugin before 2.8.5 is susceptible to arbitrary file access. The plugin does not validate user input before using it to output the content of a file, which can allow an attacker to read arbitrary files on the server, obtain sensitive information, modify data, and/or execute unauthorized operations.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享