WordPress 的 DynamiApps 开发的 Frontend Admin 插件存在认证绕过导致的账户接管漏洞,影响版本为 3.29.12 及更早的所有版本。 该漏洞的成因如下: 1. 函数未进行任何权限(capability)或所有权(ownership)检查; 2. 当帖子 ID 为非数字类型(例如字符串 )时, 会短路(short-circuit)其 授权检查,导致未经验证即可通过。 因此,未经身份验证的攻击者可以将表单提交路由到任意用户记录(包括管理员账户),从而覆盖目标用户的注册邮箱地址。随后,攻
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| shabti | Frontend Admin by DynamiApps | 0 ~ 3.29.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet