WordPress 5.1 CSRF µ¼ÖÂÔ¶³ÌºÅÁîÖ´Ðзì϶°²È«¹«¸æ

°ä²¼¹¦·ò 2019-03-15

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°ÏìÁìÓò


ÊÜÓ°Ïì°æ±¾£º 

WordPress 5.1.1 ֮ǰµÄ°æ±¾ (²»º¬ 5.1.1)


·ì϶¸ÅÊö


3 Ô 13 ÈÕ £¬RIPSTECH °ä²¼ÁË WordPress 5.1 CSRF ·ì϶µ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÄÚÈÝϸ½Ú¡£¹¥»÷ÕßÄܹ»Í¨¹ýºýŪָ±ê²©¿ÍµÄÖÎÀíÔ±½Ó¼û¹¥»÷ÕßÉèÖõÄÍøÕ¾À´ÊÕÊÜÈÎºÎÆôÓÃÁËÆÀÂÛµÄWordPressÍøÕ¾¡£Ò»µ©Êܺ¦ÖÎÀíÔ±½Ó¼û¶ñÒâÍøÕ¾ £¬¾Í»áÔÚºó¶ÜÕë¶ÔÖ¸±êWordPress²©¿ÍÔËÐпçÕ¾µãÒªÇóαÔ죨CSRF£©·ì϶ £¬¶ø²»»áÊܵ½Êܺ¦ÕßÈ·°ÑÎÈ¡£CSRF·ì϶ÀûÓÃÁ˶à¸öÂß¼­È±µãºÍËãÕÊÃýÎó £¬ÕâЩÃýÎóÔÚ×éӦʱ»áµ¼ÖÂÔ¶³ÌÖ´ÐдúÂëºÍÆëÈ«µÄÕ¾µãÊÕÊÜ¡£


·ì϶´æÔÚÓÚ5.1.1֮ǰµÄWordPress°æ±¾ÖÐ £¬Äܹ»Ê¹ÓÃĬÈÏÉèÖýøÐÐÀûÓá£


³¬¹ý33£¥µÄ»¥ÁªÍøÍøÕ¾Ê¹ÓÃWordPress¡£Ë¼¿¼µ½ÆÀÂÛÊDz©¿ÍµÄÖ÷ÌâÖ°Äܲ¢ÇÒĬÈÏÇé¿öÏÂÒÑÆôÓà £¬¸Ã·ì϶»áÓ°ÏìÊý°ÙÍò¸öÍøÕ¾¡£


·ì϶ÏêÇé


ÔÚ WordPress µÄ´¦Öùý³ÌÖÐÓÉÓÚҪʵÏÖһЩ¸öÐÔµÄÔ­Òò £¬WordPress²¢Ã»ÓÐÕë¶ÔÆÀÂ۵İ䲼×öCSRFÏÞ¶È £¬ÄÇô¹¥»÷Õ߾ͿÉÄÜʹÓÃCSRF¹¥»÷À´¹¥»÷WordPressÖÎÀíԱʹÆäͨ¹ýÆäȨÏÞ´´½¨ÆÀÂÛ¡£


WordPressÊÔͼͨ¹ýÔÚÆÀÂÛ±íµ¥ÖÐΪÖÎÀíÔ±ÌìÉúÒ»¸ö¶î±íµÄËæ»úÊýÀ´½â¾öÕâ¸öÎÊÌâ¡£µ±ÖÎÀíÔ±Ìá½»ÆÀÂÛ²¢ÌṩÓÐЧµÄËæ»úÊýʱ £¬ÆÀÂÛ½«ÔÚ²»¾­¹ýÈκÎËãÕʺ¯ÊýµÄÇé¿öÏ´´½¨¡£ÈôÊÇËæ»úÊýÎÞЧ £¬ÆÀÂÛÈԻᴴ½¨ £¬µ«»á±»ËãÕʺ¯Êý´¦Öá£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


Äܹ»¿´µ½ÆÀÂÛͨ³£ÊÇwp_filter_ksesÀ´ÕƹÜËãÕʵÄ¡£wp_filter_kses½öÔÊÐí½öÓÐ href ÊôÐ﵀ a ±êÇ©¡£


ÈôÊÇÊÇÈçÏÂÕâÖÖÇé¿ö£º´´½¨ÆÀÂÛµÄÓû§Õ¼ÓÐunfiltered_htmlȨÏÞ £¬²¢ÇÒûÓÐÌṩÓÐЧµÄËæ»úÊý £¬ÔòÓà wp_filter_post_kses À´ËãÕÊ×¢½â¡£


wp_filter_post_kses ËäÈÔ»áɾ³ýÈκοÉÄܵ¼Ö¿çÕ¾µã¾ç±¾·ì϶µÄ HTML ÏóÕ÷ºÍÊôÐÔ¡£µ«ÔÊÐíÁËһЩÆäËûµÄ³£¼ûÊôÐԺñÈrel¡£


WordPress ÔÚ´¦ÖÃÆÀÂÛÖÐµÄ a ±êÇ©µÄÊôÐÔʱ³½»áͨ¹ýÈçÏ´úÂë £¬½«ÊôÐÔ´¦ÖÃΪ¼üÖµ¶Ô¹ØÏµ¼üÊÇÊôÐÔµÄÃû³Æ £¬ÖµÊÇÊôÐÔÖµ¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾



WordPress ¶øºó²é³­relÊôÐÔÊÇ·ñ±»ÉèÖá£Ö»ÓÐͨ¹ý wp_filter_post_kses ¹ýÂË×¢½â £¬ÄÜÁ¦ÉèÖôËÊôÐÔ¡£°´ÈçÏ·½Ê½´¦Öá£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


±êÌâÊôÐÔÖµÓÃË«ÒýºÅÀ¨ÆðÀ´(µÚ 3018 ÐÐ)¡£ÕâÒâζ׏¥»÷ÕßÄܹ»Í¨¹ý×¢Èë¹ØºÏtitleÊôÐԵĶî±íË«ÒýºÅÀ´×¢Èë¶î±íµÄ HTML ÊôÐÔ¡£


ÀýÈ磺title='XSS " onmouseover=alert(1) id="'

ÀíÂÛÉÏ ½«»áÔì³É

¶øºóÔÚ¾­¹ý´¦Öúó¸ÃÆÀÂÛ¼´»á±» WordPress ´æ´¢ÈëÊý¾Ý¿â¡£


¹¥»÷ÕßÔÚ´´½¨¶ñÒâ×¢½âºó»ñȡԶ³ÌÖ´ÐдúÂëµÄÏÂÒ»²½ÊÇ»ñÈ¡ÖÎÀíÔ±Ö´ÐÐ×¢ÈëµÄJavaScript¡£ÆÀÂÛÏÔʾÔÚÖ¸±êWordPress²©¿ÍµÄǰ¶Ë¡£ WordPress×ÔÉí²»ÊÜX-Frame-Options±êÍ·µÄ±£»¤¡£ÕâÒâζ×ÅÆÀÂÛÄܹ»ÏÔʾÔÚ¹¥»÷ÕßÍøÕ¾Éϵݵ²Ø