Exploitation Summary
EIP tracks 2 public exploits for CVE-2023-26326. PoCs published by omarelshopky, mesudmammad1.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2023-26326 (BuddyForms unauthenticated insecure deserialization) chained with CVE-2024-2961 (glibc iconv vulnerability) to achieve RCE on PHP 8.3.x systems. The exploit leverages `php://filter` to bypass deserialization gadget chain limitations and delivers a reverse shell.
Description
The BuddyForms WordPress plugin, in versions prior to 2.7.8, was affected by an unauthenticated insecure deserialization issue. An unauthenticated attacker could leverage this issue to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present.
Exploits (2)
This repository contains a functional exploit for CVE-2023-26326 (BuddyForms unauthenticated insecure deserialization) chained with CVE-2024-2961 (glibc iconv vulnerability) to achieve RCE on PHP 8.3.x systems. The exploit leverages `php://filter` to bypass deserialization gadget chain limitations and delivers a reverse shell.
This repository contains a functional exploit for CVE-2023-26326, leveraging a deserialization vulnerability in the BuddyForms WordPress plugin. The exploit chains CVE-2024-2961 to achieve remote code execution via `php://filter` manipulation, bypassing PHP 8+ restrictions.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H