看板 Bugtraq 關於我們 聯絡資訊
Advisory ID: HTB23183 Product: Bitrix Site Manager Vendor: Bitrix, Inc Vulnerable Version(s): 12.5.13 and probably prior Tested Version: 12.5.13 Advisory Publication: November 6, 2013 [without technical details] Vendor Notification: November 6, 2013=20 Vendor Patch: November 12, 2013=20 Public Disclosure: December 11, 2013=20 Vulnerability Type: Insufficient Verification of Data Authenticity [CWE-345= ] CVE Reference: CVE-2013-6788 Risk Level: Medium=20 CVSSv2 Base Score: 6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P) Solution Status: Fixed by Vendor Discovered and Provided: High-Tech Bridge Security Research Lab ( https://w= ww.htbridge.com/advisory/ )=20 ---------------------------------------------------------------------------= -------------------- Advisory Details: High-Tech Bridge Security Research Lab discovered vulnerability in Bitrix S= ite Manager, which can be exploited to spoof user's identity and read, modi= fy or delete pre-ordered items in customer's basket.=20 1) User Identity Spoofing in Bitrix Site Manager: CVE-2013-6788 The vulnerability exists due to insufficient verification of supplied data = authenticity when displaying pre-order items in customer's basket in the e-= Store Module of Bitrix Site Manager. A remote unauthenticated user can chan= ge "BITRIX_SM_SALE_UID" cookie, view another user's basket and perform cert= ain actions, e.g. add or delete items in the basket. The e-Store Module mus= t be installed on the system and knowledge of a valid "BITRIX_SM_SALE_UID" = cookie is required. This value can be easily guessed using simple brute-for= ce techniques, since the application increases its value by 1 with every ne= w customer.=20 Below are exploitation instructions for this vulnerability. You will need t= o open two different browsers with plugins that allow cookie management. 1. Open your first browser 2. Visit the following URL http://[host]/buy/cms.php and add items to the b= asket. 3. You will be redirected to the following URL: http://[host]/personal/cart= =2Ephp=20 4. Record your "BITRIX_SM_SALE_UID" cookie value. 5. Open your second browser and navigate to the following URL: http://[host= ]/personal/cart.php 6. Change the value of your "BITRIX_SM_SALE_UID" cookie to the one you reco= rded before and delete all other cookies. 7. Refresh the page http://[host]/personal/cart.php. You will see pre-order= ed items of another user. ---------------------------------------------------------------------------= -------------------- Solution: Update "sale" module to version 14.0.1 More Information: http://www.bitrixsoft.com/products/cms/versions.php?module=3Dsale ---------------------------------------------------------------------------= -------------------- References: [1] High-Tech Bridge Advisory HTB23183 - User Identity Spoofing in Bitrix S= ite Manager [2] Bitrix Site Manager - http://www.bitrixsoft.com/products/cms/index.php = - With over 60,000 installations and #3 rating in the list of the most popu= lar commercial CMS worldwide, the software is an ultimate choice for corpor= ate portals, online stores, community sites and news services. [3] Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - in= ternational in scope and free for public use, CVE=C2=AE is a dictionary of = publicly known information security vulnerabilities and exposures. [4] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to = developers and security practitioners, CWE is a formal list of software wea= kness types. [5] ImmuniWeb=C2=AE - http://www.htbridge.com/immuniweb/ - is High-Tech Bri= dge's proprietary web application security assessment solution with SaaS de= livery model that combines manual and automated vulnerability testing. ---------------------------------------------------------------------------= -------------------- Disclaimer: The information provided in this Advisory is provided "as is" a= nd without any warranty of any kind. Details of this Advisory may be update= d in order to provide as accurate information as possible. The latest versi= on of the Advisory is available on web page [1] in the References.