WordPress 的 Insert or Embed Articulate Content into WordPress 插件在 4.3000000023 及之前的所有版本中,由于对 zip 压缩包中的文件上传处理不安全,因此存在任意文件上传漏洞。这使得未经验证的攻击者能够在受影响站点的服务器上上传包含 phar 文件的 zip 文件,从而有可能实现远程代码执行。
[!IMPORTANT] CVSS: 8.8(高危) [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H]
软件类型: 插件
软件标识: insert-or-embed-articulate-content-into-wordpress
受影响版本: <= 4.3000000023
git clone https://github.com/hunThubSpace/CVE-2024-0757-Exploit.git && cd CVE-2024-0757-Exploit
pip install -r requirements.txt
python3 exploit.py