cve/2022/CVE-2022-0594.md

20 lines
1.1 KiB
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2022-0594](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0594)
![](https://img.shields.io/static/v1?label=Product&message=Professional%20Social%20Sharing%20Buttons%2C%20Icons%20%26%20Related%20Posts%20%E2%80%93%20Shareaholic&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=9.7.6%3C%209.7.6%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-863%20Incorrect%20Authorization&color=brighgreen)
### Description
The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.
### POC
#### Reference
- https://wpscan.com/vulnerability/4de9451e-2c8d-4d99-a255-b027466d29b1
#### Github
- https://github.com/20142995/sectool
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates