¡¾Îó²îͨ¸æ¡¿WordPress Easy WP SMTP²å¼þ0 dayÎó²î

Ðû²¼Ê±¼ä 2020-12-15

0x00 Îó²î¸ÅÊö

CVE  ID

ÔÝÎÞ

ʱ  ¼ä

2020-12-15

Àà  ÐÍ

Éè¼Æ¹ýʧ

µÈ  ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

ÊÇ

Ó°Ïì¹æÄ£

1.4.2¼°Ö®Ç°°æ±¾

 

0x01 Îó²îÏêÇé

image.png

 

WordPressÊÇʹÓÃPHP¿ª·¢µÄ²©¿Íƽ̨£¬£¬£¬£¬£¬£¬£¬Óû§¿ÉÒÔÔÚÖ§³ÖPHPºÍMySQLÊý¾Ý¿âµÄЧÀÍÆ÷ÉϼÜÉèÊôÓÚ×Ô¼ºµÄÍøÕ¾£¬£¬£¬£¬£¬£¬£¬Ò²¿ÉÒÔ°Ñ WordPress¿´³ÉÒ»¸öÄÚÈÝÖÎÀíϵͳ£¨CMS£©À´Ê¹Óᣡ£¡£WordPress Easy WP SMTPÊÇÒ»¸ödzÒ×µÄWP SMTP²å¼þ£¬£¬£¬£¬£¬£¬£¬×°Öúó¿ÉÒÔÉèÖò¢Í¨¹ýSMTPЧÀÍÆ÷·¢Ë͵ç×ÓÓʼþ¡£¡£¡£

¿ËÈÕ£¬£¬£¬£¬£¬£¬£¬WordPress ÐÞ¸´ÁËEasy WP SMTP²å¼þÖеÄÒ»¸ö0dayÎó²î£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÖØÖÃÖÎÀíÔ±ÃÜÂë¡¢ÔÚ²©¿ÍÉÏ×°ÖÃÁ÷Ã¥²å¼þµÈ¡£¡£¡£ÏÖÔÚ£¬£¬£¬£¬£¬£¬£¬¸Ã²å¼þ±»×°ÖÃÔÚ500,000¶à¸öÕ¾µãÉÏ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒÄ¿½ñ¸ÃÎó²îÒѾ­·ºÆð±»Ê¹ÓÃÇéÐΡ£¡£¡£

Îó²îÏêÇ飺

WP SMTP²å¼þ 1.4.2¼°Ö®Ç°°æ±¾°üÀ¨Ò»ÏЧ£¬£¬£¬£¬£¬£¬£¬¿ÉΪվµã·¢Ë͵ÄËùÓеç×ÓÓʼþ£¨±êÍ·ºÍÕýÎÄ£©½¨Éèµ÷ÊÔÈÕÖ¾£¬£¬£¬£¬£¬£¬£¬È»ºó½«Æä´æ´¢ÔÚ×°ÖÃÎļþ¼ÐÖС£¡£¡£

Easy WP SMTP²å¼þʹÓõĵ÷ÊÔÈÕ־λÓÚ²å¼þµÄ×°ÖÃÎļþ¼Ð¡°/wp-content/plugins/easy-wp-smtp/¡±ÖУ¬£¬£¬£¬£¬£¬£¬¸ÃÈÕÖ¾ÊǰüÀ¨Ëæ»úÃû³ÆµÄÎı¾Îļþ£¨Èç5fcdb91308506_debug_log.txt£©¡£¡£¡£Easy WP SMTP²å¼þµÄÎļþ¼ÐûÓÐÈκÎindex.htmlÎļþ£¬£¬£¬£¬£¬£¬£¬Òò´ËÔÚÆôÓÃÁËĿ¼ÁбíµÄЧÀÍÆ÷ÉÏ£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔ²éÕÒ²¢Éó²éÈÕÖ¾£º

image.png

È»ºó£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔÖ´ÐÐͨÀýµÄÓû§Ãûö¾ÙɨÃ裬£¬£¬£¬£¬£¬£¬ÒÔ²éÕÒÖÎÀíÔ±µÇ¼Ãû£¬£¬£¬£¬£¬£¬£¬Èçͨ¹ýREST API£º

image.png

¹¥»÷ÕßÒ²¿ÉÒÔʹÓÃauthor achiveɨÃè(/?author=1)Ö´ÐÐÏàͬµÄʹÃü¡£¡£¡£

¹¥»÷ÕßʹÓôËÎó²îÔÚÈÕÖ¾ÖбêʶÖÎÀíÔ±ÕÊ»§£¬£¬£¬£¬£¬£¬£¬²¢ÊµÑéÖØÖÃÖÎÀíÔ±ÕÊ»§µÄÃÜÂ룺

image.png

ÃÜÂëÖØÖÃÀú³Ì½«´øÓÐÃÜÂëÖØÖÃÁ´½ÓµÄµç×ÓÓʼþ·¢Ë͵½adminÕÊ»§£¬£¬£¬£¬£¬£¬£¬²¢ÇҴ˵ç×ÓÓʼþ»á¼Í¼ÔÚEasy WP SMTPµÄµ÷ÊÔÈÕÖ¾ÖС£¡£¡£

image.png

 

¹¥»÷ÕßÔÚÖØÖÃÃÜÂëºó»á¼ûµ÷ÊÔÈÕÖ¾£¬£¬£¬£¬£¬£¬£¬»ñÈ¡ÖØÖÃÁ´½Ó£¬£¬£¬£¬£¬£¬£¬²¢¿ØÖƸÃÕ¾µãµÄÖÎÀíÔ±ÕÊ»§¡£¡£¡£

image.png

 

 

0x02 ´¦Öóͷ£½¨Òé

Easy WP SMTP²å¼þµÄ¿ª·¢Ö°Ô±Í¨¹ý½«²å¼þµÄµ÷ÊÔÈÕÖ¾ÒÆµ½WordPressÈÕÖ¾Îļþ¼ÐÖÐÀ´ÐÞ¸´ÁË´ËÎó²î£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ1.4.4°æ±¾¡£¡£¡£

ÏÂÔØÁ´½Ó£º

https://wordpress.org/plugins/easy-wp-smtp/#developers

0x03 ²Î¿¼Á´½Ó

https://wordpress.org/plugins/easy-wp-smtp/

https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/

https://securityaffairs.co/wordpress/112218/hacking/easy-wp-smtp-wordpress-plugin-flaw.html?

0x04 ʱ¼äÏß

2020-12-12  WordPress¸üÐÂÇ徲ͨ¸æ

2020-12-15  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png