SureTriggers <= 1.0.78 - Authorization Bypass due to Missing Empty Value Check to Unauthenticated Administrative User Creation
100Vexday Risk Score
Corrige ahora. Ella explotación observada por VulnCheck y tiene exploit funcional público.
ssvc Actcvss 8.1epss 76%
de la publicación al arma2 días
Publicada en NVD10 abr
1ª PoC+2d
metasploit13 mar
VulnCheck9 abr
probabilidad de explotación
76%top 1% de las CVE
explotación observada
síVulnCheck
7 exploit(s) público(s)
The SureTriggers: All-in-One Automation Platform plugin for WordPress is vulnerable to an authentication bypass leading to administrative account creation due to a missing empty value check on the 'secret_key' value in the 'autheticate_user' function in all versions up to, and including, 1.0.78. This makes it possible for unauthenticated attackers to create administrator accounts on the target website when the plugin is installed and activated but not configured with an API key.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
brainstormforce · OttoKit: All-in-One Automation PlatformPoCs públicas encontradas — 7
vulncheckvulncheck.com/xdb/7b8560a2e6f7no verificadovulncheckvulncheck.com/xdb/8666255309a0no verificadovulncheckvulncheck.com/xdb/b641181bf013no verificadovulncheckvulncheck.com/xdb/17bc52884d9dno verificadovulncheckvulncheck.com/xdb/92d3118dad48no verificadovulncheckvulncheck.com/xdb/d9c97322f69eno verificadovulncheckvulncheck.com/xdb/b3300d6ddffeno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
https://plugins.trac.wordpress.org/browser/suretriggers/trunk/src/Controllers/RestController.php#L59https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3266499%40suretriggers%2Ftrunk&old=3264905%40suretriggers%2Ftrunk&sfp_email=&sfph_mail=https://www.wordfence.com/threat-intel/vulnerabilities/id/ec017311-f150-4a14-a4b4-b5634f574e2b?source=cve