HackTips.

页面数据均来自于CVE官方,仅调用Api进行查询

1@1042.net

CVE编号CVE-2024-11638
发布日期2025-03-10T06:00:01.257Z
更新日期2025-03-10T14:17:07.290Z
状态PUBLISHED
受影响的供应商Unknown
受影响的产品Gtbabel
描述The Gtbabel WordPress plugin before 6.6.9 does not ensure that the URL to perform code analysis upon belongs to the blog which could allow unauthenticated attackers to retrieve a logged in user (such as admin) cookies by making them open a crafted URL as the request made to analysed the URL contains such cookies.

参考链接:

Image Additional Image