跳转到帖子

Wordpress LiteSpeed Cache plugin cookie theft

recommended_posts

发布于
  • Members

Wordpress LiteSpeed Cache plugin cookie theft

Disclosed
09/04/2024
Created
09/17/2024

Description

This module exploits an unauthenticated account takeover vulnerability in LiteSpeed Cache, a Wordpress plugin that currently has around 6 million active installations. In LiteSpeed Cache versions prior to 6.5.0.1, when the Debug Logging feature is enabled, the plugin will log admin cookies to the /wp-content/debug.log endpoint which is accessible without authentication. The Debug Logging feature in the plugin is not enabled by default. The admin cookies found in the debug.log can be used to upload and execute a malicious plugin containing a payload.

Author(s)

  • Rafie Muhammad
  • jheysel-r7

Platform

Linux,PHP,Unix,Windows

Architectures

php, cmd

Development

  • Source Code
  • History
  • 查看数 701
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…