CVE ID: CVE-2023-4631
취약점 유형: IP 주소 스푸핑
설명: DoLogin Security WordPress 플러그인은 버전 3.6 이하에서 IP 주소 스푸핑에 취약합니다. 이는 요청 로깅 및 로그인 제한을 위해 IP 주소 정보를 가져오는 위치에 대한 제한이 충분하지 않기 때문입니다. 공격자는 X-Forwarded-For 헤더에 다른 IP 주소를 제공하여 로그에 기록되도록 할 수 있으며, 이를 통해 로그인을 차단하도록 설정된 IP 주소를 우회하는 데 사용될 수 있습니다.
재현 단계:
- x-forwarded-for 헤더를 포함하여 로그인 요청을 보냅니다. 예: X-Forwarded-For: 8.8.8.8.
- "로그인 시도 로그"에서 변조된 IP 주소를 확인합니다.
참고 자료:
- https://wpscan.com/vulnerability/28613fc7-1400-4553-bcc3-24df1cee418e
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4631
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/dologin/dologin-security-36-ip-address-spoofing