CSRF vulnerability in Multisite Post...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Description ----------- ================ CSRF vulnerability in Multisite Post Duplicator could allow an attacker to do almost anything an admin user can do Vulnerability ------------- ================ Contains a CSRF vulnerability which can copy content from one site of a multisite installation to another. This could be used to add arbitrary HTML to the front-end of the site (which could be used for defacement, harvesting login credentials from authenticated users, or could be used to do virtually anything a logged-in admin user can do). This could also be used to view content not meant to be published. Proof of concept ---------------- ================ Some of these values may need adjusting depending on the post IDs, blog IDs, etc. <form method=\"POST\" action=\"http://localhost/wp-admin/tools.php?page=mpd\";> <input type=\"text\" name=\"mpd-post-status\" value=\"draft\"> <input type=\"text\" name=\"mdp-prefix\" value=\"&lt;script&gt;alert(1)&lt;/script&gt;\"> <input...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息