CVE-2020-8772: WordPress InfiniteWP <1.9.4.5 - Authorization Bypass

CVE-2020-8772: WordPress InfiniteWP <1.9.4.5 - Authorization Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2020-8772: WordPress InfiniteWP <1.9.4.5 - Authorization Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-8772: wordpress InfiniteWP <1.9.4.5 – Authorization Bypass

漏洞描述

WordPress InfiniteWP plugin before 1.9.4.5 for WordPress contains an authorization bypass vulnerability via a missing authorization check in iwp_mmb_set_request in init.php. An attacker who knows the username of an administrator can log in, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized operations.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享