2018-10-29 13:29:09 2019-01-28 14:22:41

Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.

Vector

NETWORK

Complexity

LOW

Authentication

NONE

Confidentiality

COMPLETE

Integrity

COMPLETE

Availability

COMPLETE
Advisory Patch Confirmed Link
https://github.com/wuzhicms/wuzhicms/issues/157