CVE-2022-1386: WordPress Fusion Builder <3.6.2 - Server-Side Request Forgery

CVE-2022-1386: WordPress Fusion Builder <3.6.2 - Server-Side Request Forgery-渗透云记 - 专注于网络安全与技术分享
CVE-2022-1386: WordPress Fusion Builder <3.6.2 - Server-Side Request Forgery
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-1386: WordPress Fusion Builder <3.6.2 – Server-Side Request Forgery

漏洞描述

WordPress Fusion Builder plugin before 3.6.2 is susceptible to server-side request forgery. The plugin does not validate a parameter in its forms, which can be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. An attacker can potentially interact with hosts on the server's local network, bypass firewalls, and access control measures.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享