¡¾Îó²îͨ¸æ¡¿WordPress Easy WP SMTP²å¼þ0 dayÎó²î

Ðû²¼Ê±¼ä 2020-12-15

0x00 Îó²î¸ÅÊö

CVE  ID

ÔÝÎÞ

ʱ  ¼ä

2020-12-15

Àà  ÐÍ

Éè¼Æ¹ýʧ

µÈ  ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

1.4.2¼°Ö®Ç°°æ±¾

 

0x01 Îó²îÏêÇé

image.png

 

WordPressÊÇʹÓÃPHP¿ª·¢µÄ²©¿Íƽ̨£¬ £¬£¬Óû§¿ÉÒÔÔÚÖ§³ÖPHPºÍMySQLÊý¾Ý¿âµÄЧÀÍÆ÷ÉϼÜÉèÊôÓÚ×Ô¼ºµÄÍøÕ¾£¬ £¬£¬Ò²¿ÉÒÔ°Ñ WordPress¿´³ÉÒ»¸öÄÚÈÝÖÎÀíϵͳ£¨CMS£©À´Ê¹Óᣠ¡£¡£WordPress Easy WP SMTPÊÇÒ»¸ödzÒ×µÄWP SMTP²å¼þ£¬ £¬£¬×°Öúó¿ÉÒÔÉèÖò¢Í¨¹ýSMTPЧÀÍÆ÷·¢Ë͵ç×ÓÓʼþ¡£ ¡£¡£

¿ËÈÕ£¬ £¬£¬WordPress ÐÞ¸´ÁËEasy WP SMTP²å¼þÖеÄÒ»¸ö0dayÎó²î£¬ £¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÖØÖÃÖÎÀíÔ±ÃÜÂë¡¢ÔÚ²©¿ÍÉÏ×°ÖÃÁ÷Ã¥²å¼þµÈ¡£ ¡£¡£ÏÖÔÚ£¬ £¬£¬¸Ã²å¼þ±»×°ÖÃÔÚ500,000¶à¸öÕ¾µãÉÏ£¬ £¬£¬²¢ÇÒÄ¿½ñ¸ÃÎó²îÒѾ­·ºÆð±»Ê¹ÓÃÇéÐΡ£ ¡£¡£

Îó²îÏêÇ飺

WP SMTP²å¼þ 1.4.2¼°Ö®Ç°°æ±¾°üÀ¨Ò»ÏЧ£¬ £¬£¬¿ÉΪվµã·¢Ë͵ÄËùÓеç×ÓÓʼþ£¨±êÍ·ºÍÕýÎÄ£©½¨Éèµ÷ÊÔÈÕÖ¾£¬ £¬£¬È»ºó½«Æä´æ´¢ÔÚ×°ÖÃÎļþ¼ÐÖС£ ¡£¡£

Easy WP SMTP²å¼þʹÓõĵ÷ÊÔÈÕ־λÓÚ²å¼þµÄ×°ÖÃÎļþ¼Ð¡°/wp-content/plugins/easy-wp-smtp/¡±ÖУ¬ £¬£¬¸ÃÈÕÖ¾ÊǰüÀ¨Ëæ»úÃû³ÆµÄÎı¾Îļþ£¨Èç5fcdb91308506_debug_log.txt£©¡£ ¡£¡£Easy WP SMTP²å¼þµÄÎļþ¼ÐûÓÐÈκÎindex.htmlÎļþ£¬ £¬£¬Òò´ËÔÚÆôÓÃÁËĿ¼ÁбíµÄЧÀÍÆ÷ÉÏ£¬ £¬£¬¹¥»÷Õß¿ÉÒÔ²éÕÒ²¢Éó²éÈÕÖ¾£º

image.png

È»ºó£¬ £¬£¬¹¥»÷Õß¿ÉÒÔÖ´ÐÐͨÀýµÄÓû§Ãûö¾ÙɨÃ裬 £¬£¬ÒÔ²éÕÒÖÎÀíÔ±µÇ¼Ãû£¬ £¬£¬Èçͨ¹ýREST API£º

image.png

¹¥»÷ÕßÒ²¿ÉÒÔʹÓÃauthor achiveɨÃè(/?author=1)Ö´ÐÐÏàͬµÄʹÃü¡£ ¡£¡£

¹¥»÷ÕßʹÓôËÎó²îÔÚÈÕÖ¾ÖбêʶÖÎÀíÔ±ÕÊ»§£¬ £¬£¬²¢ÊµÑéÖØÖÃÖÎÀíÔ±ÕÊ»§µÄÃÜÂ룺

image.png

ÃÜÂëÖØÖÃÀú³Ì½«´øÓÐÃÜÂëÖØÖÃÁ´½ÓµÄµç×ÓÓʼþ·¢Ë͵½adminÕÊ»§£¬ £¬£¬²¢ÇҴ˵ç×ÓÓʼþ»á¼Í¼ÔÚEasy WP SMTPµÄµ÷ÊÔÈÕÖ¾ÖС£ ¡£¡£

image.png

 

¹¥»÷ÕßÔÚÖØÖÃÃÜÂëºó»á¼ûµ÷ÊÔÈÕÖ¾£¬ £¬£¬»ñÈ¡ÖØÖÃÁ´½Ó£¬ £¬£¬²¢¿ØÖƸÃÕ¾µãµÄÖÎÀíÔ±ÕÊ»§¡£ ¡£¡£

image.png

 

 

0x02 ´¦Öóͷ£½¨Òé

Easy WP SMTP²å¼þµÄ¿ª·¢Ö°Ô±Í¨¹ý½«²å¼þµÄµ÷ÊÔÈÕÖ¾ÒÆµ½WordPressÈÕÖ¾Îļþ¼ÐÖÐÀ´ÐÞ¸´ÁË´ËÎó²î£¬ £¬£¬½¨ÒéÉý¼¶ÖÁ1.4.4°æ±¾¡£ ¡£¡£

ÏÂÔØÁ´½Ó£º

https://wordpress.org/plugins/easy-wp-smtp/#developers

0x03 ²Î¿¼Á´½Ó

https://wordpress.org/plugins/easy-wp-smtp/

https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/

https://securityaffairs.co/wordpress/112218/hacking/easy-wp-smtp-wordpress-plugin-flaw.html?

0x04 ʱ¼äÏß

2020-12-12  WordPress¸üÐÂÇ徲ͨ¸æ

2020-12-15  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png