Knit Pay 插件支持 Cashfree、Instamojo、Razorpay、PayPal 等多种支付方式,该插件在 9.6.1.0 及更早的所有版本中存在权限提升漏洞。漏洞成因在于 函数直接从一个由攻击者可控的 Gravity Forms 表单字段中读取目标角色——该字段通过 Feed 配置中的 进行设置——并将此值直接传入 函数,而未对传入的值进行白名单校验。这使得拥有订阅者(Subscriber)及以上权限的已认证攻击者,可以在提交表单时篡改隐藏的角色字段值,从而将自身权限提升至管理员(Administ
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| knitpay | Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more | ≤ 9.6.1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| knitpay | Knit Pay – Cashfree, Instamojo, Razorpay, PayPal and more | 0 ~ 9.6.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet