JustBoil.me Images Plugin for TinyMCE contains an exposed dialog interface that could lead to potential security vulnerabilities. The plugin's dialog-v4.htm file is accessible without proper access controls, which may allow unauthorized access to image upload functionality.
PoC代码[已公开]
id: justboil-me-image-upload
info:
name: JustBoil.me Images Plugin - Exposed Image Upload
author: 0xr2r
severity: medium
description: |
JustBoil.me Images Plugin for TinyMCE contains an exposed dialog interface that could lead to potential security vulnerabilities. The plugin's dialog-v4.htm file is accessible without proper access controls, which may allow unauthorized access to image upload functionality.
reference:
- https://cxsecurity.com/issue/WLB-2019050108
metadata:
verified: true
max-request: 1
fofa-query: body="/plugins/generic/tinymce/plugins/justboil.me/"
shodan-query: inurl:"/plugins/generic/tinymce/plugins/justboil.me/"
tags: justboil,tinymce,plugin,exposure,misconfig,vuln
http:
- method: GET
path:
- "{{BaseURL}}/plugins/generic/tinymce/plugins/justboil.me/dialog-v4.htm"
matchers-condition: and
matchers:
- type: word
part: body
words:
- "JustBoil.me Images Plugin"
- "TinyMCE"
- "upload_infobar"
condition: and
- type: word
part: header
words:
- "text/html"
- type: status
status:
- 200
# digest: 4b0a00483046022100b5096049ecf0d84742385bb4a625c76dbd9c41b9dc4e5bbb0320d837720906b40221009b8c729f582e702062ca977534856ce98f55d9f2543dc656b3fe82feb985ee4c:922c64590222798bb761d5b6d8e72950