CVE-2020-10257: ThemeREX Addons – Remote Code Execution

CVE-2020-10257: ThemeREX Addons - Remote Code Execution-渗透云记 - 专注于网络安全与技术分享
CVE-2020-10257: ThemeREX Addons – Remote Code Execution
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2020-10257: ThemeREX Addons – Remote Code Execution

漏洞描述

ThemeREX Addons plugin before 2020-03-09 for WordPress contains an access control vulnerability in the /trx_addons/v2/get/sc_layout REST API endpoint, allowing any users to execute PHP functions because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter, letting attackers execute arbitrary PHP functions, exploit requires no authentication.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享