CVE-2024-0881: Combo Blocks < 2.2.76 - Improper Access Control

CVE-2024-0881: Combo Blocks < 2.2.76 - Improper Access Control-渗透云记 - 专注于网络安全与技术分享
CVE-2024-0881: Combo Blocks < 2.2.76 - Improper Access Control
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-0881: Combo Blocks < 2.2.76 – Improper Access Control

漏洞描述

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel WordPress plugin before 2.2.76 does not prevent password protected posts from being displayed in the result of some unauthenticated AJAX actions, allowing unauthenticated users to read such posts

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享