WordPress 插件 Groundhogg——CRM、新闻通讯与营销自动化工具——在所有版本(最高至 4.9 版)中存在权限提升漏洞。该漏洞源于 函数中对 参数缺乏所有权验证和权限检查,导致任何具备 能力的已认证用户,无需拥有 或 权限,即可将联系人的关联 WordPress 用户 ID 随意更改为任意账户。 这使得具备销售代表(sales_rep)或更高级别权限的已认证攻击者能够通过以下方式提升权限至管理员:首先,将联系人链接到管理员的 WordPress 用户 ID;其次,创建一条包含 替换标签的备注,以触
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | ≤ 4.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | 0 ~ 4.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet