WordPress 的 LearnDash LMS 插件在 5.1.5 及以下版本中存在不受限制的文件类型上传漏洞。该漏洞源于 函数中输入验证不足:该函数遍历整个数组,但仅对第一个文件进行校验。这使得具有订阅者(subscriber)及以上权限、且注册在启用作业上传功能的课程中的认证攻击者,能够向服务器的 目录上传任意不允许的文件类型(包括 PHP 文件)。 需要注意的是,只有当默认服务器配置被修改以允许文件执行时,上传的文件才可用于远程代码执行(RCE)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| StellarWP | LearnDash LMS | ≤ 5.1.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| StellarWP | LearnDash LMS | 0 ~ 5.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet