# Uix Shortcodes – Compatible with Gutenberg <= 1.9.9 - 未认证的任意shortcode执行漏洞
## 漏洞概述
Uix Shortcodes – Compatible with Gutenberg插件在WordPress中存在任意短代码执行漏洞,影响所有版本直至包括1.9.9。
## 影响版本
所有版本直至1.9.9
## 细节
该软件允许用户执行不正确验证值即运行`do_shortcode`的操作,导致未经过身份验证的攻击者可以执行任意短代码。
## 影响
未经过身份验证的攻击者可以执行任意短代码。
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9772.yaml | POC详情 |
标题: Uix Shortcodes – Compatible with Gutenberg <= 1.9.9 - Unauthenticated Arbitrary Shortcode Execution -- 🔗来源链接
标签:
神龙速读标题: frontpage-init.php in uix-shortcodes/trunk/shortcodes/templates/default – WordPress Plugin Repository -- 🔗来源链接
标签:
暂无评论