跳转到帖子

Wordpress POST SMTP Account Takeover

recommended_posts

发布于
  • Members

Wordpress POST SMTP Account Takeover

Disclosed
01/10/2024
Created
11/29/2024

Description

The POST SMTP WordPress plugin prior to 2.8.7 is affected by a privilege escalation where an unauthenticated user is able to reset the password of an arbitrary user. This is done by requesting a password reset, then viewing the latest email logs to find the associated password reset email.

Author(s)

  • h00die
  • Ulysses Saicha

Development

  • Source Code
  • History
  • 查看数 704
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…