CVE-2023-46615
MEDIUMKD Coming Soon < 1.7 - PHP Object Injection via Untrusted Data Deserialization
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2023-46615. PoCs published by RandomRobbieBF.
AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2023-46615, demonstrating unauthenticated PHP object injection in the KD Coming Soon WordPress plugin via the `cetitle` parameter. The PoC includes a crafted HTTP request with a serialized payload that can lead to remote code execution if a suitable POP chain is present.
Description
Deserialization of Untrusted Data vulnerability in Kalli Dan. KD Coming Soon.This issue affects KD Coming Soon: from n/a through 1.7.
Exploits (1)
This repository contains a functional proof-of-concept exploit for CVE-2023-46615, demonstrating unauthenticated PHP object injection in the KD Coming Soon WordPress plugin via the `cetitle` parameter. The PoC includes a crafted HTTP request with a serialized payload that can lead to remote code execution if a suitable POP chain is present.
References (1)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N