CVE-2024-52433: My Geo Posts Free <= 1.2 - PHP Object Injection

CVE-2024-52433: My Geo Posts Free <= 1.2 - PHP Object Injection-渗透云记 - 专注于网络安全与技术分享
CVE-2024-52433: My Geo Posts Free <= 1.2 - PHP Object Injection
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-52433: My Geo Posts Free <= 1.2 – PHP Object Injection

漏洞描述

The My Geo Posts Free plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 1.2 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享