CVE-2023-45878: Gibbon LMS <= v25.0.01 - File Upload to RCE

CVE-2023-45878: Gibbon LMS <= v25.0.01 - File Upload to RCE-渗透云记 - 专注于网络安全与技术分享
CVE-2023-45878: Gibbon LMS <= v25.0.01 - File Upload to RCE
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-45878: Gibbon LMS <= v25.0.01 – File Upload to rce

漏洞描述

Gibbon LMS versions 25.0.1 and earlier are vulnerable to an Arbitrary File Upload that can lead to Remote Code Execution (RCE). The issue stems from the rubrics_visualise_saveAjax.php endpoint, which, notably, does not require authentication. Because of this, unauthenticated attackers could potentially upload malicious PHP files and execute arbitrary code on the server.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享