CVE-2024-9989: Crypto <= 2.15 - Authentication Bypass

CVE-2024-9989: Crypto <= 2.15 - Authentication Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2024-9989: Crypto <= 2.15 - Authentication Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-9989: Crypto <= 2.15 – Authentication Bypass

漏洞描述

The Crypto plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.15. This is due a to limited arbitrary method call to 'crypto_connect_ajax_process::log_in' function in the 'crypto_connect_ajax_process' function. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the username.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享