PoC-in-GitHub/2025/CVE-2025-14502.json
2026-01-16 09:45:18 +09:00

33 lines
No EOL
1.6 KiB
JSON
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

[
{
"id": 1134825870,
"name": "WordPress-News-and-Blog-Designer-Bundle-CVE-2025-14502",
"full_name": "Kai-One001\/WordPress-News-and-Blog-Designer-Bundle-CVE-2025-14502",
"owner": {
"login": "Kai-One001",
"id": 76192879,
"avatar_url": "https:\/\/avatars.githubusercontent.com\/u\/76192879?v=4",
"html_url": "https:\/\/github.com\/Kai-One001",
"user_view_type": "public"
},
"html_url": "https:\/\/github.com\/Kai-One001\/WordPress-News-and-Blog-Designer-Bundle-CVE-2025-14502",
"description": "WordPress的News and Blog Designer Bundle插件在1.1及之前所有版本中存在通过template参数导致的本地文件包含漏洞。该漏洞使得未经身份验证的攻击者能够包含并执行服务器上的任意.php文件从而运行这些文件中的任何PHP代码。在允许上传和包含.php文件类型的场景下攻击者可利用此漏洞绕过访问控制、获取敏感数据或实现代码执行。",
"fork": false,
"created_at": "2026-01-15T09:00:28Z",
"updated_at": "2026-01-15T23:23:26Z",
"pushed_at": "2026-01-15T09:15:56Z",
"stargazers_count": 1,
"watchers_count": 1,
"has_discussions": false,
"forks_count": 0,
"allow_forking": true,
"is_template": false,
"web_commit_signoff_required": false,
"topics": [],
"visibility": "public",
"forks": 0,
"watchers": 1,
"score": 0,
"subscribers_count": 0
}
]