CVE-2021-24278: WordPress Contact Form 7 <2.3.4 - Arbitrary Nonce Generation

CVE-2021-24278: WordPress Contact Form 7 <2.3.4 - Arbitrary Nonce Generation-渗透云记 - 专注于网络安全与技术分享
CVE-2021-24278: WordPress Contact Form 7 <2.3.4 - Arbitrary Nonce Generation
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-24278: WordPress Contact Form 7 <2.3.4 – Arbitrary Nonce Generation

漏洞描述

WordPress Contact Form 7 before version 2.3.4 allows unauthenticated users to use the wpcf7r_get_nonce AJAX action to retrieve a valid nonce for any WordPress action/function.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享