CVE-2023-5003: Active Directory Integration WP Plugin < 4.1.10 - Log Disclosure

CVE-2023-5003: Active Directory Integration WP Plugin < 4.1.10 - Log Disclosure-渗透云记 - 专注于网络安全与技术分享
CVE-2023-5003: Active Directory Integration WP Plugin < 4.1.10 - Log Disclosure
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-5003: Active Directory Integration WP Plugin < 4.1.10 – Log Disclosure

漏洞描述

The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享