WordPress 的 Product Designer App 插件在包括 1.1.3 在内的所有版本中均存在目录遍历(Directory Traversal)漏洞,该漏洞可通过 参数触发。这使得未经身份验证的攻击者能够读取服务器上的任意文件内容,而这些文件可能包含敏感信息。该端点唯一的身份验证机制依赖于一个 nonce(一次性令牌)和一个 token,而这两个值均作为 JavaScript 全局变量公开输出在渲染了 短代码的任何页面上,因此匿名访客可以轻易获取它们。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| productdesignerapp | Product Designer App | 0 ~ 1.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet