¡¾·ì϶¹«¸æ¡¿WordPress Easy WP SMTP²å¼þ0 day·ì϶

°ä²¼¹¦·ò 2020-12-15

0x00 ·ì϶¸ÅÊö

CVE  ID

ÔÝÎÞ

ʱ  ¼ä

2020-12-15

Àà  ÐÍ

Éè¼ÆÃýÎó

µÈ  ¼¶

¸ßΣ

Ô¶³ÌÀûÓÃ

ÊÇ

Ó°ÏìÁìÓò

1.4.2¼°Ö®Ç°°æ±¾

 

0x01 ·ì϶ÏêÇé

image.png

 

WordPressÊÇʹÓÃPHP¿ª·¢µÄ²©¿Íƽ̨£¬Óû§Äܹ»ÔÚÖ§³ÖPHPºÍMySQLÊý¾Ý¿âµÄ·þÎñÆ÷ÉϼÜÉèÊôÓÚ×Ô¼ºµÄÍøÕ¾£¬Ò²Äܹ»°Ñ WordPressµ±×÷Ò»¸öÄÚÈÝÖÎÀíϵͳ£¨CMS£©À´Ê¹Óá£WordPress Easy WP SMTPÊÇÒ»¸ö¼òÒ×µÄWP SMTP²å¼þ£¬×°ÖúóÄܹ»ÅäÖò¢Í¨¹ýSMTP·þÎñÆ÷·¢Ë͵ç×ÓÓʼþ¡£

½üÈÕ£¬WordPress ½¨¸´ÁËEasy WP SMTP²å¼þÖеÄÒ»¸ö0day·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶³ÁÖÃÖÎÀíÔ±ÃÜÂë¡¢ÔÚ²©¿ÍÉÏ×°ÖÃµØÆ¦²å¼þµÈ¡£Ä¿Ç°£¬¸Ã²å¼þ±»×°ÖÃÔÚ500,000¶à¸öÕ¾µãÉÏ£¬²¢ÇÒµ±Ç°¸Ã·ì϶ÒѾ­³öÏÖ±»ÀûÓÃÇé¿ö¡£

·ì϶ÏêÇ飺

WP SMTP²å¼þ 1.4.2¼°Ö®Ç°°æ±¾Ô̺¬Ò»ÏîÖ°ÄÜ£¬¿ÉΪվµã·¢Ë͵ÄËùÓеç×ÓÓʼþ£¨±êÍ·ºÍÕýÎÄ£©´´½¨µ÷ÊÔÈÕÖ¾£¬¶øºó½«Æä´æ´¢ÔÚ×°ÖÃÎļþ¼ÐÖС£

Easy WP SMTP²å¼þʹÓõĵ÷ÊÔÈÕ־λÓÚ²å¼þµÄ×°ÖÃÎļþ¼Ó×°/wp-content/plugins/easy-wp-smtp/¡±ÖУ¬¸ÃÈÕÖ¾ÊÇÔ̺¬Ëæ»úÃû³ÆµÄÎı¾Îļþ£¨Èç5fcdb91308506_debug_log.txt£©¡£Easy WP SMTP²å¼þµÄÎļþ¼ÐûÓÐÈκÎindex.htmlÎļþ£¬Òò¶øÔÚÆôÓÃÁËĿ¼ÁбíµÄ·þÎñÆ÷ÉÏ£¬¹¥»÷ÕßÄܹ»²éÕÒ²¢²é¿´ÈÕÖ¾£º

image.png

¶øºó£¬¹¥»÷ÕßÄܹ»Ö´ÐÐͨÀýµÄÓû§Ãûö¾ÙɨÃ裬ÒÔ²éÕÒÖÎÀíÔ±µÇ¼Ãû£¬Èçͨ¹ýREST API£º

image.png

¹¥»÷ÕßÒ²Äܹ»Ê¹ÓÃauthor achiveɨÃè(/?author=1)Ö´ÐÐÒ»ÑùµÄ¹¤×÷¡£

¹¥»÷ÕßÀûÓô˷ì϶ÔÚÈÕÖ¾ÖбêʶÖÎÀíÔ¹ØÊ»§£¬²¢³¢ÊÔ³ÁÖÃÖÎÀíÔ¹ØÊ»§µÄÃÜÂ룺

image.png

ÃÜÂë³ÁÖùý³Ì½«´øÓÐÃÜÂë³ÁÖÃÁ´½ÓµÄµç×ÓÓʼþ·¢Ë͵½adminÕÊ»§£¬²¢ÇҴ˵ç×ÓÓʼþ»á¼Í¼ÔÚEasy WP SMTPµÄµ÷ÊÔÈÕÖ¾ÖС£

image.png

 

¹¥»÷ÕßÔÚ³ÁÖÃÃÜÂëºó½Ó¼ûµ÷ÊÔÈÕÖ¾£¬»ñÈ¡³ÁÖÃÁ´½Ó£¬²¢½ÚÔì¸ÃÕ¾µãµÄÖÎÀíÔ¹ØÊ»§¡£

image.png

 

 

0x02 ´ëÖý¨Òé

Easy WP SMTP²å¼þµÄ¿ª·¢ÈËԱͨ¹ý½«²å¼þµÄµ÷ÊÔÈÕÖ¾ÒÆµ½WordPressÈÕÖ¾Îļþ¼ÐÖÐÀ´½¨¸´ÁË´Ë·ì϶£¬½¨ÒéÉý¼¶ÖÁ1.4.4°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://wordpress.org/plugins/easy-wp-smtp/#developers

0x03 ²Î¿¼Á´½Ó

https://wordpress.org/plugins/easy-wp-smtp/

https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/

https://securityaffairs.co/wordpress/112218/hacking/easy-wp-smtp-wordpress-plugin-flaw.html?

0x04 ¹¦·òÏß

2020-12-12  WordPress¸üа²È«²¼¸æ

2020-12-15  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png