目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2023-45966 PoC — remak42 代码问题漏洞

来源
关联漏洞
标题: remak42 代码问题漏洞 (CVE-2023-45966)
Description:remak42是一个自托管、轻量级且简单(但功能齐全)的评论引擎,不会监视用户。 remak42 1.12.1及之前版本存在安全漏洞,该漏洞源于存在服务器请求伪造(SSRF)漏洞。
Description
Blind SSRF in umputun/remark42 <= 1.12.1
介绍
# CVE-2023-45966
Blind SSRF in umputun/remark42 <= 1.12.1
[Suggested description]
An issue was found in umputun/remark42 <= 1.12.1. Malicious JSON in POST request to /api/v1/comment?site=<SITE_ID> leads to Blind SSRF due to missing `title` field and insufficient filtering of `url` field in comment creation request.
------------------------------------------
[Additional Information]
Fixed in commit: efceed6
------------------------------------------
[VulnerabilityType Other]
CWE-918: Server Side Request Forgery
------------------------------------------
[Vendor of Product]
https://github.com/umputun
------------------------------------------
[Affected Product Code Base]
Affected version: umputun/remark42 <= 1.12.1
------------------------------------------
[Affected Component]
/api/v1/comment
------------------------------------------
[Attack Type]
Remote
------------------------------------------
[Impact Code execution]
false
------------------------------------------
[Impact Denial of Service]
false
------------------------------------------
[Impact Escalation of Privileges]
false
------------------------------------------
[Impact Information Disclosure]
true
------------------------------------------
[Attack Vectors]
An attacker able to send crafted JSON 
------------------------------------------
[Discoverer]
Dmitry Kuramin (Jet Infosystems, jet.su)
------------------------------------------
[Reference]
https://jet.su/vuln
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →