Share
## https://sploitus.com/exploit?id=095321CA-7E7D-560B-BF1F-0A01CDB2E813
# CVE-2021-24545

ํ˜„์žฌ๋Š” plugin์œผ๋กœ ๋ฐฐํฌ๊ฐ€ ์ค‘๋‹จ๋˜์–ด ์žˆ๋Š” ํ”Œ๋Ÿฌ๊ทธ์ธ์—์„œ ๋ฐœ๊ฒฌ๋œ XSS ์ทจ์•ฝ์ ์ž…๋‹ˆ๋‹ค. 
WordPress Plugin HTML Author Bio description XSS

ํ•ด๋‹น ์ทจ์•ฝ์ ์€ /wp-admin/profile.php์—์„œ description ๋งค๊ฐœ ๋ณ€์ˆ˜์— ๋Œ€ํ•œ ๋ถ€์ ์ ˆํ•œ ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ๋กœ ์ธํ•ด ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.
์›๊ฒฉ์˜ ๊ณต๊ฒฉ์ž๋Š” ์•…์˜์ ์œผ๋กœ ์กฐ์ž‘๋œ HTTP ์š”์ฒญ์„ ์ „์†กํ•˜์—ฌ ๊ณต๊ฒฉํ•  ์ˆ˜ ์žˆ๋‹ค.

# ์„ค์น˜ ๋ฐ ์‹คํ–‰ ์ˆœ์„œ

#### 1. WordPress ์„ค์น˜
์„ค์น˜๋ฅผ ์ง„ํ–‰ํ•  ๋•Œ, docker-compose.yml ํŒŒ์ผ์—์„œ ํฌํŠธํฌ์›Œ๋”ฉ์„ ์ง„ํ–‰ํ•ด์ฃผ์‹œ๊ธฐ ๋ฐ”๋ž๋‹ˆ๋‹ค. 
<pre> $ docker-compose up  </pre>

#### 2. WordPress initial & Plugin installation
http://[web-server ip]:port/๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
๊ธฐ๋ณธ์ ์ธ ์„ค์น˜๋ฅผ ์ง„ํ–‰ํ•ฉ๋‹ˆ๋‹ค.
WP-HTML-Author-Bio-master.zip ํŒŒ์ผ์„ ์ด์šฉํ•˜์—ฌ ํ”Œ๋Ÿฌ๊ทธ์ธ์„ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค. 

#### 3. PoC

์•„๋ž˜ ๊ฒฝ๋กœ๋กœ ๋“ค์–ด๊ฐ‘๋‹ˆ๋‹ค.

http://[web-server ip]:port/wp-admin/profile.php

Biographical Info์— img ํƒœ๊ทธ๋ฅผ ์ด์šฉํ•œ XSS payload๋ฅผ ์‚ฝ์ž…ํ•ฉ๋‹ˆ๋‹ค. 

![image](https://user-images.githubusercontent.com/43310843/140014897-f2f7c6b9-3560-40ab-9120-2bd5311f8a43.png)

๊ทธ๋ฆฌ๊ณ  wordpress blog์— ๋“ค์–ด๊ฐ€๋ฉด ์•„๋ž˜ ๊ทธ๋ฆผ๊ณผ ๊ฐ™์ด XSS๊ฐ€ ์‹คํ–‰๋˜๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

![image](https://user-images.githubusercontent.com/43310843/140014892-4e7e6592-da5c-4fef-bfb5-0b70a0ee3164.png)

# ์ฃผ์˜ ์‚ฌํ•ญ
#### ์œ„ ์ทจ์•ฝ์ ์„ ๋ถˆ๋ฒ•์œผ๋กœ ์•…์šฉํ•  ์‹œ, ๋ฒ•์  ์ฑ…์ž„์„ ์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
#### If you illegally exploit the above vulnerabilities, you will not be held liable.
#### docker ๋ฒ„์ „์„ ์ตœ์‹ ํ™” ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

# ์ถœ์ฒ˜ 
https://wpscan.com/vulnerability/64267134-9d8c-4e0c-b24f-d18692a5775e