CVE-2020-8658
Htaccess <= 1.8.1 - Cross-Site Request Forgery
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The BestWebSoft Htaccess plugin through 1.8.1 for WordPress allows wp-admin/admin.php?page=htaccess.php&action=htaccess_editor CSRF. The flag htccss_nonce_name passes the nonce to WordPress but the plugin does not validate it correctly, resulting in a wrong implementation of anti-CSRF protection. In this way, an attacker is able to direct the victim to a malicious web page that modifies the .htaccess file, and takes control of the website.
El plugin BestWebSoft Htaccess versiones hasta 1.8.1 para WordPress, permite un ataque de tipo CSRF de wp-admin/admin.php?page=htaccess.php&action=htaccess_editor. El flag htccss_nonce_name pasa el nonce hacia WordPress pero el plugin no lo comprueba correctamente, resultando en una implementación incorrecta de la protección anti-CSRF. De esta manera, un atacante puede direccionar a la víctima a una página web maliciosa que modifica el archivo .htaccess y toma el control del sitio web.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-02-01 CVE Published
- 2020-02-06 CVE Reserved
- 2023-06-10 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://wordpress.org/plugins/htaccess/#developers | Third Party Advisory | |
https://wpvulndb.com/vulnerabilities/10060 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/V1n1v131r4/Exploiting-WP-Htaccess-by-BestWebSoft-Plugin/blob/master/README.md | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Bestwebsoft Search vendor "Bestwebsoft" | Htaccess Search vendor "Bestwebsoft" for product "Htaccess" | <= 1.8.1 Search vendor "Bestwebsoft" for product "Htaccess" and version " <= 1.8.1" | wordpress |
Affected
|