diff --git a/weekender-newspaper-wp-theme-open-redirect.yaml b/weekender-newspaper-wp-theme-open-redirect.yaml new file mode 100644 index 0000000000..b047695b8a --- /dev/null +++ b/weekender-newspaper-wp-theme-open-redirect.yaml @@ -0,0 +1,19 @@ +id: weekender-newspaper-wp-theme-open-redirect + +info: + name: WordPress Attitude Themes 1.1.1 Open Redirection + author: 0x_Akoko + reference: https://cxsecurity.com/issue/WLB-2020040103 + severity: low + tags: wp,redirect + +requests: + - method: GET + path: + - "{{BaseURL}}/wp-content/themes/weekender/friend.php?id=MTA0&link=aHR0cHM6Ly9leGFtcGxlLmNvbQ==" + + matchers: + - type: regex + regex: + - '(?m)^(?:Location\s*?:\s*?)(?:https?://|//)?(?:[a-zA-Z0-9\-_\.@]*)example\.com.*$' + part: header