ืคื’ื™ืขื•ืช ื”ืžืืคืฉืจืช ื”ื—ืœืคื” ืฉืœ ืงื•ื“ JavaScript ื‘ืืžืฆืขื•ืช ื”ืชื•ืกืฃ OptinMonster WordPress

ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช (CVE-2021-39341) ื‘ืชื•ืกืฃ OptinMonster WordPress, ื‘ืขืœ ื™ื•ืชืจ ืžืžื™ืœื™ื•ืŸ ื”ืชืงื ื•ืช ืคืขื™ืœื•ืช ื•ืžืฉืžืฉ ืœื”ืฆื’ืช ื”ืชืจืื•ืช ื•ื”ืฆืขื•ืช ืงื•ืคืฆื•ืช, ื”ืžืืคืฉืจื•ืช ืœืš ืœืžืงื ืืช ืงื•ื“ ื”-JavaScript ืฉืœืš ื‘ืืชืจ ื‘ืืžืฆืขื•ืช ื”ืชื•ืกืฃ ืฉืฆื•ื™ืŸ. ื”ืคื’ื™ืขื•ืช ืชื•ืงื ื” ื‘ืžื”ื“ื•ืจื” 2.6.5. ื›ื“ื™ ืœื—ืกื•ื ื’ื™ืฉื” ื“ืจืš ืžืคืชื—ื•ืช ืฉื ืชืคืกื• ืœืื—ืจ ื”ืชืงื ืช ื”ืขื“ื›ื•ืŸ, ืžืคืชื—ื™ OptinMonster ื‘ื™ื˜ืœื• ืืช ื›ืœ ืžืคืชื—ื•ืช ื”ื’ื™ืฉื” ืฉืœ API ืฉื ื•ืฆืจื• ื‘ืขื‘ืจ ื•ื”ื•ืกื™ืคื• ื”ื’ื‘ืœื•ืช ืขืœ ื”ืฉื™ืžื•ืฉ ื‘ืžืคืชื—ื•ืช ืืชืจ ื•ื•ืจื“ืคืจืก ืœืฉื™ื ื•ื™ ืžืกืขื•ืช ืคืจืกื•ื ืฉืœ OptinMonster.

ื”ื‘ืขื™ื” ื ื’ืจืžื” ืขืœ ื™ื“ื™ ื ื•ื›ื—ื•ืช REST-API /wp-json/omapp/v1/support, ืฉืืœื™ื• ื ื™ืชืŸ ื”ื™ื” ืœื’ืฉืช ืœืœื ืื™ืžื•ืช - ื”ื‘ืงืฉื” ื‘ื•ืฆืขื” ืœืœื ื‘ื“ื™ืงื•ืช ื ื•ืกืคื•ืช ืื ื”ื›ื•ืชืจืช Referer ืžื›ื™ืœื” ืืช ื”ืžื—ืจื•ื–ืช "https://wp .app.optinmonster.test" ื•ื›ืืฉืจ ืžื’ื“ื™ืจื™ื ืืช ืกื•ื’ ื‘ืงืฉืช ื”-HTTP ืœ-"OPTIONS" (ื ืขืงืฃ ืขืœ ื™ื“ื™ ื›ื•ืชืจืช ื”-HTTP "X-HTTP-Method-Override"). ื‘ื™ืŸ ื”ื ืชื•ื ื™ื ืฉื”ื•ื—ื–ืจื• ื‘ืขืช ื”ื’ื™ืฉื” ืœ- REST-API ื”ืžื“ื•ื‘ืจ, ื”ื™ื” ืžืคืชื— ื’ื™ืฉื” ื”ืžืืคืฉืจ ืœืฉืœื•ื— ื‘ืงืฉื•ืช ืœื›ืœ ืžื˜ืคืœ REST-API.

ื‘ืืžืฆืขื•ืช ื”ืžืคืชื— ืฉื”ื•ืฉื’, ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื‘ืฆืข ืฉื™ื ื•ื™ื™ื ื‘ื›ืœ ื‘ืœื•ืงื™ื ืงื•ืคืฆื™ื ื”ืžื•ืฆื’ื™ื ื‘ืืžืฆืขื•ืช OptinMonster, ื›ื•ืœืœ ืืจื’ื•ืŸ ื‘ื™ืฆื•ืข ืงื•ื“ ื”-JavaScript ืฉืœื•. ืœืื—ืจ ืฉื–ื›ื” ื‘ื”ื–ื“ืžื ื•ืช ืœื”ืคืขื™ืœ ืืช ืงื•ื“ ื”-JavaScript ืฉืœื• ื‘ื”ืงืฉืจ ืฉืœ ื”ืืชืจ, ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืคื ื•ืช ืžืฉืชืžืฉื™ื ืœืืชืจ ืฉืœื• ืื• ืœืืจื’ืŸ ื”ื—ืœืคื” ืฉืœ ื—ืฉื‘ื•ืŸ ืžื™ื•ื—ืก ื‘ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ื›ืืฉืจ ืžื ื”ืœ ื”ืืชืจ ื”ืคืขื™ืœ ืืช ืงื•ื“ ื”-JavaScript ื”ื—ืœื•ืคื™. ืœืื—ืจ ื’ื™ืฉื” ืœืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜, ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ื‘ื™ืฆื•ืข ืฉืœ ืงื•ื“ ื”-PHP ืฉืœื• ื‘ืฉืจืช.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”