From 27508da69c62db7c05ba48a291cf49db34967022 Mon Sep 17 00:00:00 2001 From: Roberto Nunes <46332131+Akokonunes@users.noreply.github.com> Date: Sun, 8 Aug 2021 12:32:42 +0900 Subject: [PATCH 1/2] Create grimag-open-redirect.yaml --- grimag-open-redirect.yaml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) create mode 100644 grimag-open-redirect.yaml diff --git a/grimag-open-redirect.yaml b/grimag-open-redirect.yaml new file mode 100644 index 0000000000..29f68e71d8 --- /dev/null +++ b/grimag-open-redirect.yaml @@ -0,0 +1,20 @@ +id: grimag-open-redirect + +info: + name: WordPress Grimag Themes < 1.1.1 Open Redirection + author: 0x_Akoko + description: The Grimag WordPress theme was affected by an Open Redirection security vulnerability. + reference: https://wpscan.com/vulnerability/db319d4c-7de6-4d36-90e9-86de82e9c03a + severity: low + tags: wp,wordpress,themes,redirect + +requests: + - method: GET + path: + - "{{BaseURL}}/wp-content/themes/Grimag/go.php?https://example.com" + + matchers: + - type: regex + regex: + - '(?m)^(?:Location\s*?:\s*?)(?:https?://|//)?(?:[a-zA-Z0-9\-_\.@]*)example\.com.*$' + part: header From d7b8760231a26ad56cf44a5202538722b85d3b4b Mon Sep 17 00:00:00 2001 From: sandeep Date: Sun, 8 Aug 2021 12:29:11 +0530 Subject: [PATCH 2/2] minor update --- .../wordpress/wp-grimag-open-redirect.yaml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) rename grimag-open-redirect.yaml => vulnerabilities/wordpress/wp-grimag-open-redirect.yaml (89%) diff --git a/grimag-open-redirect.yaml b/vulnerabilities/wordpress/wp-grimag-open-redirect.yaml similarity index 89% rename from grimag-open-redirect.yaml rename to vulnerabilities/wordpress/wp-grimag-open-redirect.yaml index 29f68e71d8..b8089bf787 100644 --- a/grimag-open-redirect.yaml +++ b/vulnerabilities/wordpress/wp-grimag-open-redirect.yaml @@ -1,4 +1,4 @@ -id: grimag-open-redirect +id: wp-grimag-open-redirect info: name: WordPress Grimag Themes < 1.1.1 Open Redirection @@ -6,7 +6,7 @@ info: description: The Grimag WordPress theme was affected by an Open Redirection security vulnerability. reference: https://wpscan.com/vulnerability/db319d4c-7de6-4d36-90e9-86de82e9c03a severity: low - tags: wp,wordpress,themes,redirect + tags: wordpress,wp-theme,redirect requests: - method: GET