CVE-2023-32117: Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

CVE-2023-32117: Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints-渗透云记 - 专注于网络安全与技术分享
CVE-2023-32117: Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-32117: Integrate Google Drive <= 1.1.99 – Missing Authorization via REST API Endpoints

漏洞描述

The Integrate Google Drive plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in versions up to, and including, 1.1.99. This makes it possible for unauthenticated attackers to perform a wide variety of operations, such as moving files, creating folders, copying details, and much more.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享