CVE-2022-0594: WordPress Shareaholic <9.7.6 - Information Disclosure

CVE-2022-0594: WordPress Shareaholic <9.7.6 - Information Disclosure-渗透云记 - 专注于网络安全与技术分享
CVE-2022-0594: WordPress Shareaholic <9.7.6 - Information Disclosure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2022-0594: wordpress Shareaholic <9.7.6 – Information Disclosure

漏洞描述

WordPress Shareaholic plugin prior to 9.7.6 is susceptible to information disclosure. The plugin does not have proper authorization check in one of the AJAX actions, available to both unauthenticated (before 9.7.5) and authenticated (in 9.7.5) users, allowing them to possibly obtain sensitive information such as active plugins and different versions (PHP, cURL, WP, etc.).

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享