WordPress SuperStoreFinder-wp 插件 import.php 任意文件上传漏洞

Description

WordPress SuperStoreFinder-wp 是一款内置了精确的地理位置,让客户以最简单的方式路由和到达您的商店网点的插件。WordPress SuperStoreFinder-wp 插件没有正确检查文件上传,攻击者可以将Content-Type标头设置为text/csv,并使用双扩展来绕过现有的检查,攻击者可上传恶意文件获取服务器权限。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities