From 655186fe04c1854f3c428338335ba724018841d0 Mon Sep 17 00:00:00 2001 From: Goby <50955360+gobysec@users.noreply.github.com> Date: Wed, 28 Jun 2023 18:25:00 +0800 Subject: [PATCH] Create CVE-2021-24375.md add CVE-2021-24375 --- CVE-2021-24375.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) create mode 100644 CVE-2021-24375.md diff --git a/CVE-2021-24375.md b/CVE-2021-24375.md new file mode 100644 index 0000000..b6c552d --- /dev/null +++ b/CVE-2021-24375.md @@ -0,0 +1,12 @@ +## WordPress Theme Motor File Inclusion Vulnerability(CVE-2021-24375) + +| **Vulnerability** | **WordPress Theme Motor File Inclusion Vulnerability(CVE-2021-24375)** | +| :----: | :-----| +| **Chinese name** | WordPress Motor 主题 admin-ajax.php 文件包含漏洞(CVE-2021-24375) | +| **CVSS core** | 9.8 | +| **FOFA Query** (click to view the results directly)| [body="wp-content/themes/motor"](https://en.fofa.info/result?qbase64=Ym9keT0id3AtY29udGVudC90aGVtZXMvbW90b3Ii) | +| **Number of assets affected** | 711 | +| **Description** | Motor is a professional WordPress WooCommerce Theme for dealers, retailers, shops and mechanics. WordPress Motor Theme < 3.1.0 is vulnerable to Local File Inclusion. | +| **Impact** | Attackers can use this vulnerability to read the leaked source code, database configuration files, etc., resulting in an extremely insecure website. | + +![](https://s3.bmp.ovh/imgs/2023/06/28/56a22a12996a7f9c.gif)