
Proof-of-Concept-Exploit für CVE-2024-27956 SQL-Injection im ValvePress Automatic Plugin. Erstellt Administratoren in WordPress, um Remote-Code-Ausführung zu erreichen.
Ein PoC für CVE-2024-27956, eine SQL-Injection im ValvePress Automatic Plugin. Dieser PoC nutzt die Schwachstelle aus, indem er einen Benutzer im Zielsystem erstellt und ihm Administratorrechte verleiht. Administrator in wordpress zu sein, kann zu Remote Code Execution führen.
git clone https://github.com/itzheartzz/MASS-CVE-2024-27956/
cd MASS-CVE-2024-27956
python3 exploit.py list.txt