CVE编号 | CVE-2024-11638 |
---|---|
发布日期 | 2025-03-10T06:00:01.257Z |
更新日期 | 2025-03-10T14:17:07.290Z |
状态 | PUBLISHED |
受影响的供应商 | Unknown |
受影响的产品 | Gtbabel |
描述 | The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated attackers to retrieve a logged in user (such as admin) cookies by making them open a crafted URL as the request made to analysed the URL contains such cookies. |
参考链接: