WordPress 5.1 CSRF µ¼ÖÂÔ¶³ÌÏÂÁîÖ´ÐÐÎó²îÇ徲ͨ¸æ
Ðû²¼Ê±¼ä 2019-03-15Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºÔÝÎÞ£¬£¬£¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£º¸ßΣ£¬£¬£¬£¬£¬£¬£¬ CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì¹æÄ£
ÊÜÓ°Ïì°æ±¾£º
WordPress 5.1.1 ֮ǰµÄ°æ±¾ (²»º¬ 5.1.1)
Îó²î¸ÅÊö
3 Ô 13 ÈÕ£¬£¬£¬£¬£¬£¬£¬RIPSTECH Ðû²¼ÁË WordPress 5.1 CSRF Îó²îµ¼ÖÂÔ¶³Ì´úÂëÖ´ÐеÄÄÚÈÝϸ½Ú¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýÓÕÆÄ¿µÄ²©¿ÍµÄÖÎÀíÔ±»á¼û¹¥»÷ÕßÉèÖõÄÍøÕ¾À´½ÓÊÜÈÎºÎÆôÓÃÁË̸ÂÛµÄWordPressÍøÕ¾¡£¡£¡£¡£Ò»µ©Êܺ¦ÖÎÀíÔ±»á¼û¶ñÒâÍøÕ¾£¬£¬£¬£¬£¬£¬£¬¾Í»áÔÚºǫ́Õë¶ÔÄ¿µÄWordPress²©¿ÍÔËÐпçÕ¾µãÇëÇóαÔ죨CSRF£©Îó²î£¬£¬£¬£¬£¬£¬£¬¶ø²»»áÊܵ½Êܺ¦ÕßµÄ×¢ÖØ¡£¡£¡£¡£CSRFÎó²îʹÓÃÁ˶à¸öÂ߼ȱÏݺÍÕûÀí¹ýʧ£¬£¬£¬£¬£¬£¬£¬ÕâЩ¹ýʧÔÚ×éÊÊʱ»áµ¼ÖÂÔ¶³ÌÖ´ÐдúÂëºÍÍêÕûµÄÕ¾µã½ÓÊÜ¡£¡£¡£¡£
Îó²î±£´æÓÚ5.1.1֮ǰµÄWordPress°æ±¾ÖУ¬£¬£¬£¬£¬£¬£¬¿ÉÒÔʹÓÃĬÈÏÉèÖþÙÐÐʹÓᣡ£¡£¡£
Áè¼Ý33£¥µÄ»¥ÁªÍøÍøÕ¾Ê¹ÓÃWordPress¡£¡£¡£¡£¿£¿£Ë¼Á¿µ½Ì¸ÂÛÊDz©¿ÍµÄ½¹µã¹¦Ð§²¢ÇÒĬÈÏÇéÐÎÏÂÒÑÆôÓ㬣¬£¬£¬£¬£¬£¬¸ÃÎó²î»áÓ°ÏìÊý°ÙÍò¸öÍøÕ¾¡£¡£¡£¡£
Îó²îÏêÇé
ÔÚ WordPress µÄ´¦Öóͷ£Àú³ÌÖÐÓÉÓÚҪʵÏÖÒ»Ð©ÌØÕ÷µÄÔµ¹ÊÔÓÉ£¬£¬£¬£¬£¬£¬£¬WordPress²¢Ã»ÓÐÕë¶Ô̸ÂÛµÄÐû²¼×öCSRFÏÞÖÆ£¬£¬£¬£¬£¬£¬£¬ÄÇô¹¥»÷Õß¾ÍÄܹ»Ê¹ÓÃCSRF¹¥»÷À´¹¥»÷WordPressÖÎÀíԱʹÆäͨ¹ýÆäȨÏÞ½¨Éè̸ÂÛ¡£¡£¡£¡£
WordPressÊÔͼͨ¹ýÔÚ̸ÂÛ±íµ¥ÖÐΪÖÎÀíÔ±ÌìÉúÒ»¸öÌØÁíÍâËæ»úÊýÀ´½â¾öÕâ¸öÎÊÌâ¡£¡£¡£¡£µ±ÖÎÀíÔ±Ìύ̸ÂÛ²¢ÌṩÓÐÓõÄËæ»úÊýʱ£¬£¬£¬£¬£¬£¬£¬Ì¸ÂÛ½«ÔÚ²»¾ÓÉÈκÎÕûÀíº¯ÊýµÄÇéÐÎϽ¨Éè¡£¡£¡£¡£ÈôÊÇËæ»úÊýÎÞЧ£¬£¬£¬£¬£¬£¬£¬Ì¸ÂÛÈԻὨÉ裬£¬£¬£¬£¬£¬£¬µ«»á±»ÕûÀíº¯Êý´¦Öóͷ£¡£¡£¡£¡£
¿ÉÒÔ¿´µ½Ì¸ÂÛͨ³£ÊÇwp_filter_ksesÀ´ÈÏÕæÕûÀíµÄ¡£¡£¡£¡£wp_filter_kses½öÔÊÐí½öÓÐ href ÊôÐ﵀ a ±êÇ©¡£¡£¡£¡£
ÈôÊÇÊÇÈçÏÂÕâÖÖÇéÐΣº½¨Éè̸ÂÛµÄÓû§ÓµÓÐunfiltered_htmlȨÏÞ£¬£¬£¬£¬£¬£¬£¬²¢ÇÒûÓÐÌṩÓÐÓõÄËæ»úÊý£¬£¬£¬£¬£¬£¬£¬ÔòÓà wp_filter_post_kses À´ÕûÀí×¢ÊÍ¡£¡£¡£¡£
wp_filter_post_kses ËäÈÔ»áɾ³ýÈκοÉÄܵ¼Ö¿çÕ¾µã¾ç±¾Îó²îµÄ HTML ±ê¼ÇºÍÊôÐÔ¡£¡£¡£¡£µ«ÔÊÐíÁËһЩÆäËûµÄ³£¼ûÊôÐԺñÈrel¡£¡£¡£¡£
WordPress ÔÚ´¦Öóͷ£Ì¸ÂÛÖÐµÄ a ±êÇ©µÄÊôÐÔʱ¼ä»áͨ¹ýÈçÏ´úÂ룬£¬£¬£¬£¬£¬£¬½«ÊôÐÔ´¦Öóͷ£Îª¼üÖµ¶Ô¹ØÏµ¼üÊÇÊôÐÔµÄÃû³Æ£¬£¬£¬£¬£¬£¬£¬ÖµÊÇÊôÐÔÖµ¡£¡£¡£¡£
WordPress È»ºó¼ì²érelÊôÐÔÊÇ·ñ±»ÉèÖᣡ£¡£¡£Ö»ÓÐͨ¹ý wp_filter_post_kses ¹ýÂË×¢ÊÍ£¬£¬£¬£¬£¬£¬£¬²Å»ªÉèÖôËÊôÐÔ¡£¡£¡£¡£°´ÈçÏ·½·¨´¦Öóͷ£¡£¡£¡£¡£
ÎÊÌâÊôÐÔÖµÓÃË«ÒýºÅÀ¨ÆðÀ´(µÚ 3018 ÐÐ)¡£¡£¡£¡£ÕâÒâζ׏¥»÷Õß¿ÉÒÔͨ¹ý×¢Èë±ÕºÏtitleÊôÐÔµÄÌØÊâË«ÒýºÅÀ´×¢ÈëÌØÁíÍâ HTML ÊôÐÔ¡£¡£¡£¡£
ÀýÈ磺title='XSS " onmouseover=alert(1) id="'
ÀíÂÛÉÏ ½«»áÄð³É
È»ºóÔÚ¾ÓÉ´¦Öóͷ£ºó¸Ã̸ÂÛ¼´»á±» WordPress ´æ´¢ÈëÊý¾Ý¿â¡£¡£¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ