# Hunk Companion <= 1.8.4 - 未认证任意插件安装/激活缺少授权漏洞
## 漏洞概述
Hunk Companion插件存在未授权插件安装/激活漏洞,原因是 `/wp-json/hc/v1/themehunk-import` REST API 端点缺少能力检查,这使得未经身份验证的攻击者可以安装和激活任意插件,并进一步利用这些插件实现远程代码执行。
## 影响版本
所有版本直到包括 1.8.4 均受到影响
## 漏洞细节
Hunk Companion 插件的 `/wp-json/hc/v1/themehunk-import` REST API 端点在处理请求时没有进行适当的能力检查。未经身份验证的攻击者可以通过利用这个漏洞来安装和激活任意插件。
## 影响
如果服务器上安装了其他易受攻击的插件,攻击者可以进一步利用这些插件来实现远程代码执行。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation | https://github.com/RandomRobbieBF/CVE-2024-9707 | POC详情 |
2 | he Hunk Companion Plugin for WordPress: Vulnerable to Unauthorized Plugin Installation/Activation (Versions Up to and Including 1.8.4) | https://github.com/Nxploited/CVE-2024-9707-Poc | POC详情 |
3 | The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in all versions up to, and including, 1.8.4. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-9707.yaml | POC详情 |
标题: Hunk Companion <= 1.8.4 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation/Activation -- 🔗来源链接
标签:
神龙速读标题: plugins-hunk-companion/hunk-companion/import/app/app.php at 5a3cedc7b3d35d407b210e691c53c6cb400e4051 · WordPressBugBounty/plugins-hunk-companion · GitHub -- 🔗来源链接
标签:
神龙速读