¡¾Â©¶´Í¨¸æ¡¿WordPress²å¼þ¶à¸öSQL×¢Èë©¶´

Ðû²¼Ê±¼ä 2023-01-16

0x00 ©¶´¸ÅÊö

2023Äê1ÔÂ12ÈÕ£¬Tenable ResearchµÄÑо¿ÈËÔ±¹ûÈ»Åû¶Á˶à¸öWordPress ²å¼þÖеÄSQL×¢Èë©¶´£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÒÔÐ޸Ļòɾ³ýÍøÕ¾Êý¾Ý¡¢×¢Èë¶ñÒâ½Å±¾»ò»ñµÃ¶ÔÍøÕ¾µÄÍêÈ«·ÃÎÊȨÏÞ¡£

 

0x01 ©¶´ÏêÇé

WordPress ²å¼þPaid Memberships ProÊÇÒ»¸ö»áÔ±ºÍ¶©ÔĹÜÀí¹¤¾ß£¬±»Áè¼Ý100,000¸öÍøÕ¾Ê¹Óã»WordPress ²å¼þEasy Digital Downloads ÊÇÒ»ÖÖÓÃÓÚÏúÊÛÊý×ÖÎļþµÄµç×ÓÉÌÎñ½â¾ö·½°¸£¬ÓµÓÐÁè¼Ý 50,000 ¸ö»î¶¯°²×°£»Survey MarkerÊÇÒ»¸ö±» 3,000 ¸öÍøÕ¾ÓÃÓÚÊÓ²ìºÍÊг¡Ñо¿µÄ WordPress ²å¼þ¡£

±¾´ÎÅû¶µÄ3¸öSQL×¢Èë©¶´ÏêÇéÈçÏ£¬Ä¿Ç°ÕâЩ©¶´µÄPoC/EXPÒѹûÈ»£º

CVE-ID

ÆÀ·Ö

ÃèÊö

Ó°Ï췶Χ

ÐÞ¸´°æ±¾

CVE-2023-23488

9.8

WordPress ²å¼þPaid Memberships ProÔÚSQLÓï¾äÖÐʹÓÃ/pmpro/v1/order REST·ÓÉÖеÄcode²ÎÊý֮ǰûÓнøÐÐתÒ壬´Ó¶øµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄSQL×¢Èë©¶´¡£

Paid Memberships Pro °æ±¾   < 2.9.8

Paid Memberships Pro °æ±¾ 2.9.8

CVE-2023-23489

9.8

WordPress ²å¼þEasy Digital DownloadsÔÚSQLÓï¾äÖÐʹÓÃedd_download_searchÐж¯ÖеÄs²ÎÊý֮ǰûÓнøÐÐתÒ壬´Ó¶øµ¼ÖÂδ¾­Éí·ÝÑéÖ¤µÄSQL×¢Èë©¶´¡£×¢£ºÒ×Êܹ¥»÷´úÂë¶ÔÓ¦ÓÚ./includes/ajax-functions.phpÎļþµÄedd_ajax_download_search()º¯Êý¡£

Easy Digital Downloads°æ±¾< 3.1.0.4

Easy Digital Downloads°æ±¾ 3.1.0.4

CVE-2023-23490

8.8

WordPress ²å¼þSurvey MakerÔÚSQLÓï¾äÖÐʹÓÃays_surveys_export_json Ðж¯ÖÐµÄ survey_ids ²ÎÊý֮ǰûÓÐ¶ÔÆä½øÐÐתÒ壬´Ó¶øµ¼Ö¾­¹ýÑéÖ¤µÄSQL×¢Èë©¶´¡£×¢£ºÀûÓøÃ©¶´Ðè¾­¹ýÑéÖ¤£¬µ«ÎÞÐè¹ÜÀíԱȨÏÞ¡£

Survey Maker°æ±¾   < 3.1.2

Survey Maker°æ±¾   3.1.2

 

0x02 ´¦Öý¨Òé

ĿǰÕâЩ©¶´ÒѾ­ÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿É¾¡¿ìÉý¼¶µ½ÐÞ¸´°æ±¾¡£

ÏÂÔØÁ´½Ó£º

https://wordpress.org/plugins/

 

0x03 ²Î¿¼Á´½Ó

https://www.tenable.com/security/research/tra-2023-2

https://www.bleepingcomputer.com/news/security/poc-exploits-released-for-critical-bugs-in-popular-wordpress-plugins/

 

0x04 °æ±¾ÐÅÏ¢

°æ±¾

ÈÕÆÚ

ÐÞ¸ÄÄÚÈÝ

V1.0

2023-01-16

Ê×´ÎÐû²¼

 

0x05 ¸½Â¼

¶«É­Æ½Ì¨¼ò½é

¶«É­Æ½Ì¨½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£

¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶«É­Æ½Ì¨´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©

¶àÄêÀ´£¬¶«É­Æ½Ì¨ÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·ÅÆ¶ø²»Ð¸Å¬Á¦¡£

 

¹ØÓÚ¶«É­Æ½Ì¨

¶«É­Æ½Ì¨Äþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£

¹Ø×¢ÒÔϹ«Öںţ¬»ñȡȫÇò×îÐÂÄþ¾²×ÊѶ£º

image.png