关联漏洞
介绍
# CVE-2024-27971-Note
WordPress Premmerce Permalink Manager for WooCommerce Plugin <= 2.3.10 is vulnerable to Local File Inclusion
https://patchstack.com/database/vulnerability/woo-permalink-manager/wordpress-premmerce-permalink-manager-for-woocommerce-plugin-2-3-10-local-file-inclusion-vulnerability
1. I diff woo-permalink-manager.2.3.10 and woo-permalink-manager.2.3.11

3. File: src\Admin\Admin.php => function options() call function includeTemplate(vendor\premmerce\wordpress-sdk\src\V2\FileManager\FileManager.php)

4. File: vendor\premmerce\wordpress-sdk\src\V2\FileManager\FileManager.php => function includeTemplate call function locateTemplate


4. File: views\admin\main.php

Build wordpress: docker-compose -f stack.yml up
Note: wordpress install plugin Premmerce Permalink Manager for WooCommerce and WooCommerce

5. I use pearcmd.php write pwn.php

6. Requests pwn.php

文件快照
[4.0K] /data/pocs/973d244cbbcfe00a568c2154574860a058843566
├── [1.8K] README.md
├── [ 607] stack.yml
├── [1.9M] woo-permalink-manager.2.3.10.zip
└── [1.9M] woo-permalink-manager.2.3.11.zip
0 directories, 4 files
备注
1. 建议优先通过来源进行访问。
2. 如果因为来源失效或无法访问,请发送邮件到 f.jinxu#gmail.com 索取本地快照(把 # 换成 @)。
3. 神龙已为您对 POC 代码进行快照,为了长期维护,请考虑为本地 POC 付费/捐赠,感谢您的支持。