CVE-2024-55556: InvoiceShelf <= 1.3.0 - PHP Deserialization

CVE-2024-55556: InvoiceShelf <= 1.3.0 - PHP Deserialization-渗透云记 - 专注于网络安全与技术分享
CVE-2024-55556: InvoiceShelf <= 1.3.0 - PHP Deserialization
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-55556: InvoiceShelf <= 1.3.0 – PHP Deserialization

漏洞描述

InvoiceShelf version 1.3.0 and below contains an unauthenticated PHP deserialization vulnerability that can lead to remote code execution. An attacker with knowledge of the APP_KEY can achieve remote command execution on the server through Laravel's cookie deserialization. While the vulnerability is severe, it is partially mitigated in default installations as the APP_KEY is regenerated during setup.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享