NOMISEC-RandomRobbieBF/CVE-2024-54374

NOMISEC WRITEUP
Exploit for CVE-2024-54374 - Sogrid <1.5.6 - Path Traversal
AI Analysis

The repository provides a description and proof-of-concept for CVE-2024-54374, an unauthenticated Local File Inclusion vulnerability in the Sogrid WordPress plugin (versions up to 1.5.6). The PoC demonstrates the ability to include arbitrary files within a specific directory, though it notes the limitation of only loading files inside `/wp-content/plugins/sogrid/src/admin-panel/views/`.

Attack Type
info_leak
Complexity
trivial
Reliability
reliable
MITRE ATT&CK
T1190 - Exploit Public-Facing Application
Loading exploit code...
Download ZIP Password: eip
Source
Platform Nomisec
Type poc
Files 1
Stars 0
Forks 0
Last Push Jan 03, 2025
Authors
RandomRobbieBF
Vulnerability
CVE-2024-54374
Sogrid <1.5.6 - Path Traversal
HIGH
CVSS 7.5