CVE-2025-2539: File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read

CVE-2025-2539: File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read-渗透云记 - 专注于网络安全与技术分享
CVE-2025-2539: File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-2539: File Away <= 3.9.9.0.1 – Missing Authorization to Unauthenticated Arbitrary File Read

漏洞描述

The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享