CVE-2023-6933: Better Search Replace < 1.4.5 - PHP Object Injection

CVE-2023-6933: Better Search Replace < 1.4.5 - PHP Object Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2023-6933: Better Search Replace < 1.4.5 - PHP Object Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-6933: Better Search Replace < 1.4.5 – PHP Object Injection

漏洞描述

The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享