WordPress 5.1 CSRF µ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-03-15

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºÔÝÎÞ£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì¹æÄ£


ÊÜÓ°Ïì°æ±¾£º 

WordPress 5.1.1 ֮ǰµÄ°æ±¾ (²»º¬ 5.1.1)


Îó²î¸ÅÊö


3 Ô 13 ÈÕ£¬£¬RIPSTECH Ðû²¼ÁË WordPress 5.1 CSRF Îó²îµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÄÚÈÝϸ½Ú¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕÆ­Ä¿µÄ²©¿ÍµÄÖÎÀíÔ±»á¼û¹¥»÷ÕßÉèÖõÄÍøÕ¾À´½ÓÊÜÈÎºÎÆôÓÃÁË̸ÂÛµÄWordPressÍøÕ¾¡£¡£¡£Ò»µ©Êܺ¦ÖÎÀíÔ±»á¼û¶ñÒâÍøÕ¾£¬£¬¾Í»áÔÚºǫ́Õë¶ÔÄ¿µÄWordPress²©¿ÍÔËÐпçÕ¾µãÇëÇóαÔ죨CSRF£©Îó²î£¬£¬¶ø²»»áÊܵ½Êܺ¦ÕßµÄ×¢ÖØ¡£¡£¡£CSRFÎó²îʹÓÃÁ˶à¸öÂß¼­È±ÏݺÍÕûÀí¹ýʧ£¬£¬ÕâЩ¹ýʧÔÚ×éÊÊʱ»áµ¼ÖÂÔ¶³ÌÖ´ÐдúÂëºÍÍêÕûµÄÕ¾µã½ÓÊÜ¡£¡£¡£


Îó²î±£´æÓÚ5.1.1֮ǰµÄWordPress°æ±¾ÖУ¬£¬¿ÉÒÔʹÓÃĬÈÏÉèÖþÙÐÐʹÓᣡ£¡£


Áè¼Ý33£¥µÄ»¥ÁªÍøÍøÕ¾Ê¹ÓÃWordPress¡£¡£¡£¿£¿£¿ £¿£¿£Ë¼Á¿µ½Ì¸ÂÛÊDz©¿ÍµÄ½¹µã¹¦Ð§²¢ÇÒĬÈÏÇéÐÎÏÂÒÑÆôÓ㬣¬¸ÃÎó²î»áÓ°ÏìÊý°ÙÍò¸öÍøÕ¾¡£¡£¡£


Îó²îÏêÇé


ÔÚ WordPress µÄ´¦Öóͷ£Àú³ÌÖÐÓÉÓÚҪʵÏÖÒ»Ð©ÌØÕ÷µÄÔµ¹ÊÔ­ÓÉ£¬£¬WordPress²¢Ã»ÓÐÕë¶Ô̸ÂÛµÄÐû²¼×öCSRFÏÞÖÆ£¬£¬ÄÇô¹¥»÷Õß¾ÍÄܹ»Ê¹ÓÃCSRF¹¥»÷À´¹¥»÷WordPressÖÎÀíԱʹÆäͨ¹ýÆäȨÏÞ½¨Éè̸ÂÛ¡£¡£¡£


WordPressÊÔͼͨ¹ýÔÚ̸ÂÛ±íµ¥ÖÐΪÖÎÀíÔ±ÌìÉúÒ»¸öÌØÁíÍâËæ»úÊýÀ´½â¾öÕâ¸öÎÊÌâ¡£¡£¡£µ±ÖÎÀíÔ±Ìύ̸ÂÛ²¢ÌṩÓÐÓõÄËæ»úÊýʱ£¬£¬Ì¸ÂÛ½«ÔÚ²»¾­ÓÉÈκÎÕûÀíº¯ÊýµÄÇéÐÎϽ¨Éè¡£¡£¡£ÈôÊÇËæ»úÊýÎÞЧ£¬£¬Ì¸ÂÛÈԻὨÉ裬£¬µ«»á±»ÕûÀíº¯Êý´¦Öóͷ£¡£¡£¡£


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


¿ÉÒÔ¿´µ½Ì¸ÂÛͨ³£ÊÇwp_filter_ksesÀ´ÈÏÕæÕûÀíµÄ¡£¡£¡£wp_filter_kses½öÔÊÐí½öÓÐ href ÊôÐ﵀ a ±êÇ©¡£¡£¡£


ÈôÊÇÊÇÈçÏÂÕâÖÖÇéÐΣº½¨Éè̸ÂÛµÄÓû§ÓµÓÐunfiltered_htmlȨÏÞ£¬£¬²¢ÇÒûÓÐÌṩÓÐÓõÄËæ»úÊý£¬£¬ÔòÓà wp_filter_post_kses À´ÕûÀí×¢ÊÍ¡£¡£¡£


wp_filter_post_kses ËäÈÔ»áɾ³ýÈκοÉÄܵ¼Ö¿çÕ¾µã¾ç±¾Îó²îµÄ HTML ±ê¼ÇºÍÊôÐÔ¡£¡£¡£µ«ÔÊÐíÁËһЩÆäËûµÄ³£¼ûÊôÐԺñÈrel¡£¡£¡£


WordPress ÔÚ´¦Öóͷ£Ì¸ÂÛÖÐµÄ a ±êÇ©µÄÊôÐÔʱ¼ä»áͨ¹ýÈçÏ´úÂ룬£¬½«ÊôÐÔ´¦Öóͷ£Îª¼üÖµ¶Ô¹ØÏµ¼üÊÇÊôÐÔµÄÃû³Æ£¬£¬ÖµÊÇÊôÐÔÖµ¡£¡£¡£


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾



WordPress È»ºó¼ì²érelÊôÐÔÊÇ·ñ±»ÉèÖᣡ£¡£Ö»ÓÐͨ¹ý wp_filter_post_kses ¹ýÂË×¢ÊÍ£¬£¬²Å»ªÉèÖôËÊôÐÔ¡£¡£¡£°´ÈçÏ·½·¨´¦Öóͷ£¡£¡£¡£


ÄϹ¬NGÓéÀÖ(Öйú)¹Ù·½ÍøÕ¾


ÎÊÌâÊôÐÔÖµÓÃË«ÒýºÅÀ¨ÆðÀ´(µÚ 3018 ÐÐ)¡£¡£¡£ÕâÒâζ׏¥»÷Õß¿ÉÒÔͨ¹ý×¢Èë±ÕºÏtitleÊôÐÔµÄÌØÊâË«ÒýºÅÀ´×¢ÈëÌØÁíÍâ HTML ÊôÐÔ¡£¡£¡£


ÀýÈ磺title='XSS " onmouseover=alert(1) id="'

ÀíÂÛÉÏ ½«»áÄð³É

È»ºóÔÚ¾­ÓÉ´¦Öóͷ£ºó¸Ã̸ÂÛ¼´»á±» WordPress ´æ´¢ÈëÊý¾Ý¿â¡£¡£¡£


¹¥»÷ÕßÔÚ½¨Éè¶ñÒâ×¢Êͺó»ñȡԶ³ÌÖ´ÐдúÂëµÄÏÂÒ»²½ÊÇ»ñÈ¡ÖÎÀíÔ±Ö´ÐÐ×¢ÈëµÄJavaScript¡£¡£¡£Ì¸ÂÛÏÔʾÔÚÄ¿µÄWordPress²©¿ÍµÄǰ¶Ë¡£¡£¡£ WordPress×Ô¼º²»ÊÜX-Frame-Options±êÍ·µÄ±£»£»£»¤¡£¡£¡£ÕâÒâζ×Å̸ÂÛ¿ÉÒÔÏÔʾÔÚ¹¥»÷ÕßÍøÕ¾ÉϵÄÒþ²Ø