How Serialized Cookies Led to RCE on a WordPress Website
hackerone.com | blog | #bug-bounty | #rce | #nextcloud | #php | #web-security | #wordpress | #cookies | #insecure-deserialization
Summary
A bug bounty write-up details an RCE in Nextcloud's WordPress site caused by insecure PHP deserialization in a custom theme, and explains how to identify, assess, and remediate such flaws.
- Published
- Collected
Skip to content