Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAN6thH4u+tRjwgKw0EAo6GnbctqTojku69M6c0=EvURf8Vxspw@mail.gmail.com>
Date: Sun, 24 May 2015 07:20:32 +0200
From: 0pc0deFR <0pc0defr@...il.com>
To: OSS Securty <oss-security@...ts.openwall.com>
Cc: cve-assign@...re.org
Subject: CVE Request for WP Fastest Cache plugin

CSRF vulnerability was found in WP Fastest Cache 0.8.3.4 plugin.

The vuln is found in admin.php:
        public function optionsPageRequest(){
            if(!empty($_POST)){
                if(isset($_POST["wpFastestCachePage"])){

if(preg_match("/admin\.php\?page=WpFastestCacheOptions/",
$_SERVER["REQUEST_URI"])){
                        if($_POST["wpFastestCachePage"] == "options"){
                            $this->saveOption();
                        }else if($_POST["wpFastestCachePage"] ==
"deleteCache"){
                            $this->deleteCache();
                        }else if($_POST["wpFastestCachePage"] ==
"deleteCssAndJsCache"){
                            $this->deleteCssAndJsCache();
                        }else if($_POST["wpFastestCachePage"] ==
"cacheTimeout"){
                            $this->addCacheTimeout();
                        }
                    }else{
                        die("Forbidden");
                    }
                }
            }
        }

The vuln is patched in 0.8.3.5 version.

--
Cordialement,

Kévin FALCOZ alias 0pc0deFR - Consultant Expert WordPress -
http://wordpress-expertise.fr

--
Regards,

Kévin FALCOZ aka 0pc0deFR - WordPress Expert Consultant -
http://wordpress-expertise.fr

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.