针对 WordPress 插件 Bit File Manager 版本 <= 6.5.7 中已验证身份(订阅者及以上)有限制 JavaScript 文件上传漏洞 (CVE-2024-8743) 的概念验证脚本
描述:
Bit File Manager – 100% 免费开源文件管理器和代码编辑器 WordPress 插件在包括 6.5.7 版本在内的所有版本中均存在有限制 JavaScript 文件上传漏洞。这是由于对允许的文件类型缺乏适当的检查。这使得经过身份验证的攻击者(具有订阅者及以上访问权限,并获得管理员授予的权限)能够上传 .css 和 .js 文件,从而导致存储型跨站脚本攻击。(来源:https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/file-manager/bit-file-manager-100-free-open-source-file-manager-and-code-editor-for-wordpress-657-authenticated-subscriber-limited-javascript-file-upload)
git clone https://github.com/siunam321/CVE-2024-8743-PoC.git
file-manager更新 Python 脚本 poc.py 中的 wordpressUsername、wordpressPassword、targetBaseUrl、fileManagerPostPath、attackerIpAddress 和/或 attackerPort 为您所需的值。然后运行 python3 poc.py 来执行 PoC 脚本。
PoC 视频演示:
https://github.com/user-attachments/assets/76571398-1b8c-4726-800c-9ed6c2928562