
CVE-2024-0757 の PoC エクスプロイト - WordPress への Articulate コンテンツの挿入または埋め込みによるリモートコード実行(RCE)
WordPress用プラグイン「Insert or Embed Articulate Content into WordPress」は、すべてのバージョン(4.3000000023 までを含む)において、zip アーカイブ内の安全でないファイルアップロードにより、任意のファイルアップロードが可能となる脆弱性があります。これにより、認証されていない攻撃者が影響を受けるサイトのサーバー上に phar ファイルを含む zip ファイルをアップロードできるようになり、リモートコード実行が可能になる可能性があります。
[!IMPORTANT] CVSS: 8.8 (高) [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H]
ソフトウェアタイプ: プラグイン
ソフトウェアスラッグ: insert-or-embed-articulate-content-into-wordpress
影響を受けるバージョン: <= 4.3000000023
git clone https://github.com/hunThubSpace/CVE-2024-0757-Exploit.git && cd CVE-2024-0757-Exploit
pip install -r requirements.txt
python3 exploit.py