¡¾Îó²îͨ¸æ¡¿WordPress Easy WP SMTP²å¼þ0 dayÎó²î
Ðû²¼Ê±¼ä 2020-12-150x00 Îó²î¸ÅÊö
CVE ID | ÔÝÎÞ | ʱ ¼ä | 2020-12-15 |
Àà ÐÍ | Éè¼Æ¹ýʧ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | 1.4.2¼°Ö®Ç°°æ±¾ |
0x01 Îó²îÏêÇé
WordPressÊÇʹÓÃPHP¿ª·¢µÄ²©¿Íƽ̨£¬£¬£¬Óû§¿ÉÒÔÔÚÖ§³ÖPHPºÍMySQLÊý¾Ý¿âµÄЧÀÍÆ÷ÉϼÜÉèÊôÓÚ×Ô¼ºµÄÍøÕ¾£¬£¬£¬Ò²¿ÉÒÔ°Ñ WordPress¿´³ÉÒ»¸öÄÚÈÝÖÎÀíϵͳ£¨CMS£©À´Ê¹Óᣡ£¡£WordPress Easy WP SMTPÊÇÒ»¸ödzÒ×µÄWP SMTP²å¼þ£¬£¬£¬×°Öúó¿ÉÒÔÉèÖò¢Í¨¹ýSMTPЧÀÍÆ÷·¢Ë͵ç×ÓÓʼþ¡£¡£¡£
¿ËÈÕ£¬£¬£¬WordPress ÐÞ¸´ÁËEasy WP SMTP²å¼þÖеÄÒ»¸ö0dayÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÖØÖÃÖÎÀíÔ±ÃÜÂë¡¢ÔÚ²©¿ÍÉÏ×°ÖÃÁ÷Ã¥²å¼þµÈ¡£¡£¡£ÏÖÔÚ£¬£¬£¬¸Ã²å¼þ±»×°ÖÃÔÚ500,000¶à¸öÕ¾µãÉÏ£¬£¬£¬²¢ÇÒÄ¿½ñ¸ÃÎó²îÒѾ·ºÆð±»Ê¹ÓÃÇéÐΡ£¡£¡£
Îó²îÏêÇ飺
WP SMTP²å¼þ 1.4.2¼°Ö®Ç°°æ±¾°üÀ¨Ò»ÏЧ£¬£¬£¬¿ÉΪվµã·¢Ë͵ÄËùÓеç×ÓÓʼþ£¨±êÍ·ºÍÕýÎÄ£©½¨Éèµ÷ÊÔÈÕÖ¾£¬£¬£¬È»ºó½«Æä´æ´¢ÔÚ×°ÖÃÎļþ¼ÐÖС£¡£¡£
Easy WP SMTP²å¼þʹÓõĵ÷ÊÔÈÕ־λÓÚ²å¼þµÄ×°ÖÃÎļþ¼Ð¡°/wp-content/plugins/easy-wp-smtp/¡±ÖУ¬£¬£¬¸ÃÈÕÖ¾ÊǰüÀ¨Ëæ»úÃû³ÆµÄÎı¾Îļþ£¨Èç5fcdb91308506_debug_log.txt£©¡£¡£¡£Easy WP SMTP²å¼þµÄÎļþ¼ÐûÓÐÈκÎindex.htmlÎļþ£¬£¬£¬Òò´ËÔÚÆôÓÃÁËĿ¼ÁбíµÄЧÀÍÆ÷ÉÏ£¬£¬£¬¹¥»÷Õß¿ÉÒÔ²éÕÒ²¢Éó²éÈÕÖ¾£º
È»ºó£¬£¬£¬¹¥»÷Õß¿ÉÒÔÖ´ÐÐͨÀýµÄÓû§Ãûö¾ÙɨÃ裬£¬£¬ÒÔ²éÕÒÖÎÀíÔ±µÇ¼Ãû£¬£¬£¬Èçͨ¹ýREST API£º
¹¥»÷ÕßÒ²¿ÉÒÔʹÓÃauthor achiveɨÃè(/?author=1)Ö´ÐÐÏàͬµÄʹÃü¡£¡£¡£
¹¥»÷ÕßʹÓôËÎó²îÔÚÈÕÖ¾ÖбêʶÖÎÀíÔ±ÕÊ»§£¬£¬£¬²¢ÊµÑéÖØÖÃÖÎÀíÔ±ÕÊ»§µÄÃÜÂ룺
ÃÜÂëÖØÖÃÀú³Ì½«´øÓÐÃÜÂëÖØÖÃÁ´½ÓµÄµç×ÓÓʼþ·¢Ë͵½adminÕÊ»§£¬£¬£¬²¢ÇҴ˵ç×ÓÓʼþ»á¼Í¼ÔÚEasy WP SMTPµÄµ÷ÊÔÈÕÖ¾ÖС£¡£¡£
¹¥»÷ÕßÔÚÖØÖÃÃÜÂëºó»á¼ûµ÷ÊÔÈÕÖ¾£¬£¬£¬»ñÈ¡ÖØÖÃÁ´½Ó£¬£¬£¬²¢¿ØÖƸÃÕ¾µãµÄÖÎÀíÔ±ÕÊ»§¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
Easy WP SMTP²å¼þµÄ¿ª·¢Ö°Ô±Í¨¹ý½«²å¼þµÄµ÷ÊÔÈÕÖ¾ÒÆµ½WordPressÈÕÖ¾Îļþ¼ÐÖÐÀ´ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬½¨ÒéÉý¼¶ÖÁ1.4.4°æ±¾¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://wordpress.org/plugins/easy-wp-smtp/#developers
0x03 ²Î¿¼Á´½Ó
https://wordpress.org/plugins/easy-wp-smtp/
https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/
https://securityaffairs.co/wordpress/112218/hacking/easy-wp-smtp-wordpress-plugin-flaw.html?
0x04 ʱ¼äÏß
2020-12-12 WordPress¸üÐÂÇ徲ͨ¸æ
2020-12-15 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/