WordPress Podlove Podcast Publisher是WordPress基金会的一款播客发布管理工具。 WordPress Podlove Podcast Publisher 4.5.3及之前版本存在反序列化注入漏洞,该漏洞源于create_link_item函数对文件路径验证不足,具有投稿者级别及以上权限的经过身份验证的攻击者可通过反序列化触发POP链删除服务器上的任意文件,进而可能导致远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| eteubert | Podlove Podcast Publisher | ≤ 4.5.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| eteubert | Podlove Podcast Publisher | 0 ~ 4.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet