CVE-2023-6553
Backup Migration <= 1.3.7 - Unauthenticated Remote Code Execution
The Backup Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.3.7 via the /includes/backup-heart.php file. This is due to an attacker being able to control the values passed to an include, and subsequently leverage that to achieve remote code execution. This makes it possible for unauthenticated attackers to easily execute code on the server.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
inisev · BackupBliss – Backup & Migration with Free Cloud StoragePoCs públicas encontradas — 8
githubgithub.com/Chocapikk/CVE-2023-6553★ 85githubgithub.com/motikan2010/CVE-2023-6553-PoC★ 4githubgithub.com/0x00phantom-hat/CVE-2023-6553-RCE-Exploit★ 2githubgithub.com/Harshit-Mashru/CVE-2023-6553★ 0githubgithub.com/cc3305/CVE-2023-6553★ 0githubgithub.com/joaoaugustom/WordPress_Backup_Migration-RCE_Unauthenticated★ 0exploitdbwww.exploit-db.com/exploits/52486no verificadocve_referencepacketstormsecurity.com/files/176638/WordPress-Backup-Migration-1.3.7-Remote-Command-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/176638/WordPress-Backup-Migration-1.3.7-Remote-Command-Execution.htmlhttps://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L118https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L38https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L62https://plugins.trac.wordpress.org/browser/backup-backup/tags/1.3.7/includes/backup-heart.php#L64https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3006541%40backup-backup&new=3006541%40backup-backup&sfp_email=&sfph_mail=https://www.synacktiv.com/en/publications/php-filters-chain-what-is-it-and-how-to-use-ithttps://www.wordfence.com/threat-intel/vulnerabilities/id/3511ba64-56a3-43d7-8ab8-c6e40e3b686e?source=cve