WordPress 插件 Groundhogg — CRM、通讯簿和营销自动化工具存在权限提升漏洞。该漏洞影响所有版本,包括最高版本 4.8.3,漏洞位于 函数中。 该漏洞的成因在于:该函数仅通过匹配公开硬编码常量来识别支持账户,这些常量包括用户登录名 以及邮箱地址 和 。然而,在第 238 行使用的 邮箱平等性检查并不构成安全边界,因为用户完全能够控制自己的邮箱值。 这使得攻击者可以通过构造一个用户登录名为 且用户邮箱匹配上述硬编码支持邮箱之一的账户,静默地将该账户提升为管理员权限。此外,在多站点(Multisi
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | ≤ 4.8.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | 0 ~ 4.8.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet