WordPress 插件 LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes 在 10.2.1 及以下所有版本中,存在 PHP 对象注入漏洞,该漏洞源于对不受信任输入的反序列化操作。这使得具备自定义级别及以上权限的已认证攻击者能够注入 PHP 对象。 由于受影响软件中不存在已知的 POP(Properties-Oriented Programming,面向属性编程)链,因此除非目标站点上安装了包含 POP 链的其他插件或主题,否则该漏洞本身不会产生
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| lifterlms | LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes | ≤ 10.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| lifterlms | LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes | 0 ~ 10.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet