Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-82226 — Proof-of-concept and lab for CVE-2026-82226, an unauthenticated PHP object injection in Tickera <= 3.6.0.2 via POST /cart/, with Docker reproduction and patch guidance. | Kitploit
उपकरण/GitHubGitHub/abraxas/cve-2026-82226
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & EducationLabs & Practice
GitHubabraxas/cve-2026-82226

CVE-2026-82226

Proof-of-concept and lab for CVE-2026-82226, an unauthenticated PHP object injection in Tickera <= 3.6.0.2 via POST /cart/, with Docker reproduction and patch guidance.

रिपॉजिटरी देखें
268 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Abraxas Labs - CVE-2026-82226

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-82226

CVE-2026-82226

Tickera 3.6.0.2 - Tickera

I am @abraxas_null. Loopback lab. The client is CVE-2026-82226-Abraxas-Labs.py.

Checkout unserializes the attendee. Unauthenticated cart -> process-payment. create_order maybe_unserializes owner _post_meta. Objects instantiate. Patched in 3.6.0.3. Not admin-ajax action=create_order.

CVECVE-2026-82226 · CVE.org
CWECWE-502
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductTickera
Affectedall versions through 3.6.0.2 (inclusive)
Patched3.6.0.3 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Fill a free-order checkout with a serialized object in owner_data_first_name_post_meta. create_order builds that class during payment. A POP gadget on a real autoload is RCE. The lab ships a canary class, not a gadget.


How I found it

Patchstack named object injection. I read update_cart, then create_order around the _post_meta branch.

Discover like a visitor: ticket id, COOKIEHASH, cart path, payment path, cart nonce (tickera_cart_page). POST cart_action=proceed_to_checkout with the canary in _post_meta, not in the email. Then POST process-payment with tc_payment_submit and free_orders. Follow Location. Checkout 302s. Process-payment 302s. The canary may echo into HTML before the redirect script.

Wrong turns: admin-ajax.php action=create_order (theme); Invalid cart request (wrong nonce); The cart is empty (missing tc_cart_{COOKIEHASH} or wrong ticket id); All fields marked with * are required (empty name/email); stopping at the payment 302.


The lab

Port 8088. Tickera 3.6.0.2. Public fixture page with ticket id and paths. Free orders on.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-82226-Abraxas-Labs.py

Witness: POCWitness82226 in the confirmation body or debug.log. Theme HTML, invalid cart nonce, or empty cart is not it.

Ways to lose without learning anything:

  • generic 200 hello-world HTML
  • Invalid cart request / empty cart / required fields
  • status success without unserialize / class instantiation
  • reverse shell

The fix

Update Tickera to 3.6.0.3 or newer. Re-run CVE-2026-82226-Abraxas-Labs.py against the patched build: POCWitness82226 must not appear.


References

  • CVE-2026-82226 · NVD

  • CVE-2026-82226 · CVE.org

  • patchstack.com/database/wordpress/plugin/tickera-event-ticketing-system/vulnerability/wordpress-tickera-plugin-3-6-0-2-php-object-injection-vulnerability?_s_id=cve

  • github.com/advisories/GHSA-v3jw-vq2p-6xp9

  • nvd.nist.gov/vuln/detail/CVE-2026-82226

  • Plugin directory: tickera-event-ticketing-system

  • Trac browser: plugins.trac.wordpress.org/tickera-event-ticketing-system

  • SVN tags: plugins.svn.wordpress.org/tickera-event-ticketing-system

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

टूल डाउनलोड करें