References https://nvd.nist.gov/vuln/detail/CVE-2023-53872 https://github.com/advisories/GHSA-pmxp-m64w-v7f6 https://cve.imfht.com/detail/CVE-2023-53872?lang=en https://www.exploit-db.com/exploits/51717 https://cve.cert.hr/cve/CVE-2023-53872 https://access.redhat.com/security/cve/cve-2023-53872 https://www.vulncheck.com/advisories/wpfac-os-command-injection-via-sendphp-endpoint
Related VulnerabilitiesPoCCVE-2021-24916: WordPress Qubely < 1.8.6 - Unauthenticated Email Sending福建科立讯通信指挥调度管理平台 /api/client/fax/send_fax.php 命令执行漏洞泛微云桥e-Bridge /wxthirdapi/sendWxMsg SQL 注入漏洞PoC孚盟云CRM /m/Dingding/Ajax/AjaxFormDefault.ashx sendProductMessage SQL 注入漏洞PoC泛微云桥 e-Bridge sendWxMsg 接口存在SQL注入漏洞Tosei Self-service Washing Machine /cgi-bin/tosei_datasend.php 命令执行漏洞(CVE-2026-2533)PoCCVE-2026-0829: Frontend File Manager Plugin <= 23.5 - Unauthenticated Arbitrary Email SendingPoCCVE-2024-43965: SendGrid for WordPress <= 1.4 - SQL Injection上海必智科技有限公司必智律师事务所综合管理系统send.asp currentUserID参数存在SQL注入漏洞PoC孚盟云 CRM /m/Dingding/Ajax/AjaxMailInSend.ashx SQL 注入漏洞PoC孚盟云CRM /m/Dingding/Ajax/AjaxProviderList.ashx SendMessage SQL 注入漏洞