CVE-2021-24527: Profile Builder < 3.4.9 - Improper Authentication

CVE-2021-24527: Profile Builder < 3.4.9 - Improper Authentication-渗透云记 - 专注于网络安全与技术分享
CVE-2021-24527: Profile Builder < 3.4.9 - Improper Authentication
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2021-24527: Profile Builder < 3.4.9 – Improper Authentication

漏洞描述

The Profile Builder plugin before 3.4.9 for WordPress allows unauthenticated attackers to gain administrative access by exploiting an improper authentication vulnerability in the password reset functionality. An attacker can reset the password of any user, including administrators, without proper authorization, leading to a complete site compromise.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享