Kaugelt ekspluateeritav haavatavus MyBB foorumi tarkvaras

MyBB, open-source web forum software, has several vulnerabilities that, when combined, allow for the execution of PHP code on the server. These issues are present in releases from 1.8.16 to 1.8.25 and have been fixed in update MyBB 1.8.26.

Esimene haavatavus (CVE-2021-27889) võimaldab privileege mitteomaval foorumi kasutajal sisestada JavaScripti koodi postitustesse, aruteludesse ja privaatsetesse sõnumitesse. Foorum võimaldab lisada pilte, loendeid ja multimeedia sisu spetsiaalsete siltide kaudu, mis muudetakse HTML-i struktuuriks. Koodivigas tõttu selliste siltide teisendamisel, konstruktsioon kahekordse URL-iga [img]http://xyzsomething.com/image?)http://x.com/onerror=alert(1);//[/img] muudetakse <img src="»http://xyzsomething.com/image?)&lt;a" href="»" http:="»»" x.com="»»" onerror="»alert(1);//&quot;»" target="»_blank»" rel="»noopener»" class="»mycode_url»">

The second vulnerability (CVE-2021-27890) allows for SQL command injection, enabling the execution of arbitrary code. This issue arises from the insertion of $theme[‘templateset’] into the SQL query body without proper sanitization and the execution of components ${...} through an eval call. For instance, one could trigger the execution of the PHP command passthru('ls') when processing a template with the following construction: <templateset>') AND 1=0 UNION SELECT title, '${passthru(\'ls\')}' from mybb_templates — <\/templateset>

To exploit the second vulnerability, a session with forum administrator rights is required. To gain the ability to send a request with administrative privileges, an attacker can use the first vulnerability to send a private message containing JavaScript code to the administrator, which will exploit the second vulnerability when viewed.

Allikas: opennet.ru

Osta usaldusvÀÀrne veebimajutus DDoS-kaitsega veebisaitidele, VPS VDS serverid đŸ”„ Osta usaldusvÀÀrne veebimajutus DDoS-kaitsega veebisaitidele, VPS VDS serverid - ProHoster