CVE-2020-36836: WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion

CVE-2020-36836: WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion-渗透云记 - 专注于网络安全与技术分享
CVE-2020-36836: WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-36836: wordpress WP Fastest Cache <= 0.9.0.2 – Authenticated Arbitrary File Deletion

漏洞描述

The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享