{"id":102176,"date":"2021-11-02T03:36:46","date_gmt":"2021-11-02T01:36:46","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-dopuskayushhaya-podstanovku-javascript-koda-cherez-wordpress-plagin-optinmonster"},"modified":"2021-11-02T03:36:46","modified_gmt":"2021-11-02T01:36:46","slug":"uyazvimost-dopuskayushhaya-podstanovku-javascript-koda-cherez-wordpress-plagin-optinmonster","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-dopuskayushhaya-podstanovku-javascript-koda-cherez-wordpress-plagin-optinmonster","title":{"rendered":"Vuln\u00e9rabilit\u00e9 permettant l'injection de code JavaScript via le plugin WordPress OptinMonster","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Dans le plugin WordPress OptinMonster, qui compte plus d'un million d'installations actives et est utilis\u00e9 pour le d\u00e9ploiement de notifications et d'offres contextuelles, une vuln\u00e9rabilit\u00e9 (CVE-2021-39341) a \u00e9t\u00e9 identifi\u00e9e, permettant d'injecter du code JavaScript sur un site utilisant ce plugin. La vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e dans la version 2.6.5. Pour bloquer l'acc\u00e8s via les cl\u00e9s compromises apr\u00e8s l'installation de la mise \u00e0 jour, les d\u00e9veloppeurs d'OptinMonster ont annul\u00e9 toutes les cl\u00e9s d'acc\u00e8s API pr\u00e9c\u00e9demment cr\u00e9\u00e9es et ont ajout\u00e9 des restrictions sur l'utilisation des cl\u00e9s des sites WordPress pour modifier les campagnes OptinMonster.      <\/p>\n<p>Le probl\u00e8me est caus\u00e9 par la pr\u00e9sence de l'API REST \/wp-json\/omapp\/v1\/support, \u00e0 laquelle on pouvait acc\u00e9der sans authentification \u2014 la requ\u00eate \u00e9tait ex\u00e9cut\u00e9e sans v\u00e9rifications suppl\u00e9mentaires en pr\u00e9sence dans l'en-t\u00eate Referer de la cha\u00eene \u00ab https:\/\/wp.app.optinmonster.test \u00bb et avec le type de requ\u00eate HTTP d\u00e9fini sur \u00ab OPTIONS \u00bb (red\u00e9fini \u00e0 l'aide de l'en-t\u00eate HTTP \u00ab X-HTTP-Method-Override \u00bb). Parmi les donn\u00e9es retourn\u00e9es lors de l'appel de cette API REST, se trouvait une cl\u00e9 d'acc\u00e8s qui permettait d'envoyer des requ\u00eates \u00e0 n'importe quel gestionnaire d'API REST.     <\/p>\n<p>Avec la cl\u00e9 obtenue, un attaquant pouvait modifier n'importe quel bloc contextuel affich\u00e9 par OptinMonster, y compris organiser l'ex\u00e9cution de son propre code JavaScript. En ayant la possibilit\u00e9 d'ex\u00e9cuter son code JavaScript dans le contexte du site, l'attaquant pouvait rediriger les utilisateurs vers son propre site ou mettre en place un piratage de session d'un compte privil\u00e9gi\u00e9 dans l'interface web lors de l'ex\u00e9cution du code JavaScript inject\u00e9 par un administrateur du site. Avec l'acc\u00e8s \u00e0 l'interface web, l'attaquant pouvait parvenir \u00e0 ex\u00e9cuter son code PHP sur <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/fr\/server\/dts-newyork\/\"   title=\"le serveur\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"2686\">le serveur<\/a>.<br \/>\n<br \/>Source : <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56073\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 WordPress-\u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 OptinMonster, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u0432\u043e\u0434\u0430 \u0432\u0441\u043f\u043b\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d\u0438\u0439 \u0438 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-39341), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0440\u0430\u0437\u043c\u0435\u0441\u0442\u0438\u0442\u044c \u0441\u0432\u043e\u0439 JavaScript-\u043a\u043e\u0434 \u043d\u0430 \u0441\u0430\u0439\u0442\u0435, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0435\u043c \u0443\u043a\u0430\u0437\u0430\u043d\u043d\u043e\u0435 \u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u0432 \u0432\u044b\u043f\u0443\u0441\u043a\u0435 2.6.5. \u0414\u043b\u044f \u0431\u043b\u043e\u043a\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u0447\u0435\u0440\u0435\u0437 \u0437\u0430\u0445\u0432\u0430\u0447\u0435\u043d\u043d\u044b\u0435 \u043a\u043b\u044e\u0447\u0438 \u043f\u043e\u0441\u043b\u0435 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0438 \u043e\u0431\u043d\u043e\u0432\u043b\u0435\u043d\u0438\u044f \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 OptinMonster \u0430\u043d\u043d\u0443\u043b\u0438\u0440\u043e\u0432\u0430\u043b\u0438 \u0432\u0441\u0435 \u0440\u0430\u043d\u0435\u0435 \u0441\u043e\u0437\u0434\u0430\u043d\u043d\u044b\u0435 \u043a\u043b\u044e\u0447\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a API \u0438 \u0434\u043e\u0431\u0430\u0432\u0438\u043b\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-102176","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 WordPress-\u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 OptinMonster, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u0432\u043e\u0434\u0430 \u0432\u0441\u043f\u043b\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d\u0438\u0439 \u0438 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-39341), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0440\u0430\u0437\u043c\u0435\u0441\u0442\u0438\u0442\u044c.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-dopuskayushhaya-podstanovku-javascript-koda-cherez-wordpress-plagin-optinmonster\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 JavaScript-\u043a\u043e\u0434\u0430 \u0447\u0435\u0440\u0435\u0437 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d OptinMonster | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 WordPress-\u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 OptinMonster, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u0432\u043e\u0434\u0430 \u0432\u0441\u043f\u043b\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d\u0438\u0439 \u0438 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-39341), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0440\u0430\u0437\u043c\u0435\u0441\u0442\u0438\u0442\u044c.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-dopuskayushhaya-podstanovku-javascript-koda-cherez-wordpress-plagin-optinmonster\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-11-02T01:36:46+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-11-02T01:36:46+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vuln\u00e9rabilit\u00e9 permettant l'injection de code JavaScript \u00e0 travers le plugin WordPress OptinMonster | ProHoster","description":"Dans le plugin WordPress OptinMonster, qui compte plus d'un million d'installations actives et est utilis\u00e9 pour le d\u00e9ploiement de notifications et d'offres contextuelles, une vuln\u00e9rabilit\u00e9 (CVE-2021-39341) a \u00e9t\u00e9 identifi\u00e9e, permettant d'injecter.","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-dopuskayushhaya-podstanovku-javascript-koda-cherez-wordpress-plagin-optinmonster","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c, \u0434\u043e\u043f\u0443\u0441\u043a\u0430\u044e\u0449\u0430\u044f \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 JavaScript-\u043a\u043e\u0434\u0430 \u0447\u0435\u0440\u0435\u0437 WordPress-\u043f\u043b\u0430\u0433\u0438\u043d OptinMonster | ProHoster","og:description":"\u0412 WordPress-\u0434\u043e\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0438 OptinMonster, \u0438\u043c\u0435\u044e\u0449\u0435\u043c \u0431\u043e\u043b\u0435\u0435 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u0430 \u0430\u043a\u0442\u0438\u0432\u043d\u044b\u0445 \u0443\u0441\u0442\u0430\u043d\u043e\u0432\u043e\u043a \u0438 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0435\u043c\u043e\u043c \u0434\u043b\u044f \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0432\u044b\u0432\u043e\u0434\u0430 \u0432\u0441\u043f\u043b\u044b\u0432\u0430\u044e\u0449\u0438\u0445 \u0443\u0432\u0435\u0434\u043e\u043c\u043b\u0435\u043d\u0438\u0439 \u0438 \u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d\u0438\u0439, \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2021-39341), \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0440\u0430\u0437\u043c\u0435\u0441\u0442\u0438\u0442\u044c.","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/uyazvimost-dopuskayushhaya-podstanovku-javascript-koda-cherez-wordpress-plagin-optinmonster","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-11-02T01:36:46+00:00","article:modified_time":"2021-11-02T01:36:46+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"102176","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-11-02 01:36:50","updated":"2026-02-09 21:39:46","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/102176","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=102176"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/102176\/revisions"}],"predecessor-version":[{"id":159966,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/102176\/revisions\/159966"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=102176"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=102176"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=102176"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}