多个 Newfold 插件存在认证绕过(Authentication Bypass)漏洞。 该漏洞的根源在于这些插件内置了 模块。在该模块中, 方法被注册在 过滤器上,因此会在每一个未认证的 REST API 请求中执行。该方法执行了一种类似 HMAC 的 Bearer 令牌比较,但当 返回 时,该比较会发生“退化”:PHP 将 强制转换为 ,导致原本用于加密的私有盐值退化为公开已知的常量 (即 )。与此同时,其余的哈希输入项(HTTP 方法、请求 URL、原始请求体以及 头部)完全由攻击者控制。 这意味着未认证的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Newfold | WP Plugin Web | 0 ~ 2.3.5 | - |
|
| Newfold | WP Plugin Crazy Domains | 0 ~ 2.5.2 | - |
|
| Newfold | WP Module Data | 0 ~ 2.9.7 | - |
|
| Newfold | WP Plugin Hostgator | 0 ~ 3.2.0 | - |
|
| Newfold | WP Plugin Bluehost | 0 ~ 4.19.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet