WordPress Groundhogg是WordPress基金会开源的一款集成于网站系统的客户关系管理组件。 WordPress Groundhogg 4.5.2及之前版本存在授权问题漏洞,该漏洞源于不安全的直接对象引用,通过GET /wp-json/gh/v4/contacts/<id> REST端点,权限检查仅基于角色级view_contacts能力,read_single()返回完整联系人记录而未进行对象级所有权检查,可能导致认证攻击者读取站点上任何联系人记录,包括个人身份信息、联系人元数据、所有
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | ≤ 4.5.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | 0 ~ 4.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet