← voltar
CVE-2021-29447

WordPress Authenticated XXE attack when installation is running PHP 8

CVSS 7.1 HIGHEPSS 85.7%CWE-611
Em resumo

Usuários do WordPress com permissão para enviar arquivos (como Autores) podem explorar uma falha de análise de XML na Biblioteca de Mídia para ler arquivos internos do servidor, mas apenas se o site usa PHP 8. Esta vulnerabilidade foi corrigida no WordPress 5.7.1 e versões antigas.

Detalhe técnico

Uma vulnerabilidade XXE (XML External Entity) autenticada existe na Biblioteca de Mídia do WordPress ao executar em PHP 8, permitindo que usuários com capacidade de upload façam parsing de arquivos XML maliciosos e acessem arquivos internos sensíveis através de expansão de entidades. O ataque requer permissões de upload e ambiente PHP 8; corrigido no WordPress 5.7.1+.

Resumo gerado e traduzido por IA a partir da descrição oficial.
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
PoCs públicas encontradas26
githubgithub.com/motikan2010/CVE-2021-2944743githubgithub.com/mega8bit/exploit_cve-2021-294477githubgithub.com/0xRar/CVE-2021-29447-PoC6githubgithub.com/M3l0nPan/wordpress-cve-2021-294474githubgithub.com/Vulnmachines/wordpress_cve-2021-294474githubgithub.com/dnr6419/CVE-2021-294473githubgithub.com/thomas-osgood/CVE-2021-294473githubgithub.com/elf1337/blind-xxe-controller-CVE-2021-294473githubgithub.com/Abdulazizalsewedy/CVE-2021-294472githubgithub.com/Tea-On/CVE-2021-29447-Authenticated-XXE-WordPress-5.6-5.72githubgithub.com/Val-Resh/CVE-2021-29447-POC1githubgithub.com/b-abderrahmane/CVE-2021-29447-POC1githubgithub.com/ArtemCyberLab/Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets-1githubgithub.com/magicrc/CVE-2021-294470githubgithub.com/AssassinUKG/CVE-2021-294470githubgithub.com/G01d3nW01f/CVE-2021-294470githubgithub.com/viardant/CVE-2021-294470githubgithub.com/andyhsu024/CVE-2021-294470githubgithub.com/specializzazione-cyber-security/demo-CVE-2021-29447-lezione0githubgithub.com/davids52/cve-2021-29447_auto-script0githubgithub.com/rdana55/CVE-2021-29447-PoC0githubgithub.com/danilo1992-sys/CVE-2021-294470githubgithub.com/0xricksanchez/CVE-2021-294470cve_referencepacketstormsecurity.com/files/164198/WordPress-5.7-Media-Library-XML-Injection.htmlnão verificadoexploitdbwww.exploit-db.com/exploits/50304não verificadocve_referencepacketstormsecurity.com/files/163148/XML-External-Entity-Via-MP3-File-Upload-On-WordPress.htmlnão verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →