目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2019-15896 PoC — WordPress LifterLMS插件安全漏洞

来源
关联漏洞
标题: WordPress LifterLMS插件安全漏洞 (CVE-2019-15896)
Description:WordPress LifterLMS插件3.34.5及之前版本中的class.llms.admin.import.php脚本中的‘upload_import’函数存在安全漏洞。攻击者可利用该漏洞提升权限(创建管理员帐户)、重定向用户或实施跨站脚本攻击。
Description
LifterLMS <= 3.34.5 - Unauthenticated Options Import
介绍
# CVE-2019-15896
LifterLMS &lt;= 3.34.5 - Unauthenticated Options Import

# Description

Unauthenticated Options Import, which could lead to 

- Website Redirection

- Administrator Account Creation

- Content Injection

- Stored XSS

The issues have been reported as fixed in 3.35.0. However v3.35.1 added additional input sanitisation and filtering.


How to use
---
$ python3 CVE-2019-15896.py --url http://wordpress.lan --username radmin --email admin@admin.lan
LifterLMS <= 3.34.5 - Unauthenticated Options Import
Exploit By Ramdom Robbie
Once ran check your email for the forgotten password link.
Password reset email sent to admin@admin.lan
```

Info
---

```
Requires access to login.php and working email address and the site needs to be able to send emails
```
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →