
WordPress 插件
组件名称 WC Price History for Omnibus
受影响版本 <= 2.1.4
组件 slug wc-price-history
组件链接 https://wordpress.org/plugins/wc-price-history/
漏洞类别 A3: 注入
漏洞类型 PHP 对象注入
Shop Manager(管理员及以上)
在 WC Price History for Omnibus 插件 2.1.4 及更低版本中,可以通过 WooCommerce 仪表板的 'Price History' 菜单(/wp-admin/admin.php?page=wc-price-history)中的 'Import debug data' 部分上传 JSON 文件。上传的 JSON 文件作为 wc_price_history_import_file 载荷被发送,并且 JSON 数据中 'serialized' 键的值存在 PHP 对象注入漏洞。通过该漏洞,具有 Shop Manager 权限的攻击者可以注入 PHP 对象。
虽然该插件本身没有任何已知的 POP 链,但如果目标 WordPress 站点上的其他插件或主题中存在 POP 链,攻击者就可以执行任意文件删除、敏感信息窃取和代码执行。
准备一个已安装并激活 WC Price History for Omnibus 插件 2.1.4 或更低版本的 WordPress 站点。
要激活此插件,必须首先安装并激活 WooCommerce 插件。
要测试 PHP 对象注入漏洞,请将以下 PoC_POP_Chain_Object 类添加到 wp-config.php 文件的末尾。
class PoC_POP_Chain_Object {
public $message = "";
public function __destruct() {
echo "<mark>Success PoP Chain</mark>";
echo "<br>";
echo "<mark>msg: ". $this->message ."</mark>";
}
}

接下来,创建包含以下 JSON 数据的文件。
在此 JSON 数据中,
serialized键中录入的数据采用 PHP 序列化对象格式,它会创建先前添加到wp-config.php文件中的PoC_POP_Chain_Object类的实例,并将字符串 'Exploit !!' 赋值给 message 属性。
{
"serialized": "O:20:\"PoC_POP_Chain_Object\":1:{s:7:\"message\";s:10:\"Exploit !!\";}"
}
接下来,在 WooCommerce 仪表板中导航到 'Price History' 菜单(/wp-admin/admin.php?page=wc-price-history)。在 'Import debug data' 部分,通过文件上传表单选择先前创建的 JSON 文件,并点击 'Import' 按钮进行上传。

在上传请求的响应数据中,您可以看到添加到 wp-config.php 中的 PoC_POP_Chain_Object 类的魔术方法 __destruct() 被执行,并显示以下消息。
<mark>Success PoP Chain</mark>
<br>
<mark>msg: Exploit !!</mark>

当您通过 WooCommerce 仪表板的 'Price History' 菜单(/wp-admin/admin.php?page=wc-price-history)中的 'Import debug data' 部分上传 JSON 数据并点击 'Import' 按钮时,
/wp-content/plugins/wc-price-history/app/PriorPrice/Import.php 文件中 Import 类定义的 import_file() 函数会被执行。该函数获取包含 JSON 文件的请求载荷 wc_price_history_import_file,然后从该 JSON 数据中检索键为 serialized 的数据,并通过 maybe_unserialize 函数执行反序列化。

因此,请求载荷 wc_price_history_import_file 为 JSON 格式,在未经验证的情况下反序列化键为 serialized 的序列化数据的过程中,会发生 PHP 对象注入漏洞。