WordPress 的 Gravity Forms 插件存在任意文件上传漏洞,影响版本为 3.1.0.4 及之前的所有版本,漏洞通过 函数触发。该漏洞源于字段验证流程与文件持久化流程之间的不一致:隐藏的文件上传字段会绕过扩展名校验,而被拒绝的文件在保留其完整上传状态的情况下,随后被传入 时未再次进行校验。这使得未认证的攻击者能够上传可能是可执行文件的文件,从而可能导致远程代码执行。 漏洞利用的前提条件是:目标表单中必须包含一个“文件上传”字段,且其可见性设置为“隐藏”;对于满足此条件的任何公开可访问的表单,未认证的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Gravity Forms | Gravity Forms | 0 ~ 3.1.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet