{"id":1168922,"date":"2024-02-27T15:24:24","date_gmt":"2024-02-27T17:24:24","guid":{"rendered":"https:\/\/teknomers.com\/fr\/la-vulnerabilite-du-plugin-wordpress-litespeed-met-5-millions-de-sites-en-danger\/"},"modified":"2024-02-27T15:24:28","modified_gmt":"2024-02-27T17:24:28","slug":"la-vulnerabilite-du-plugin-wordpress-litespeed-met-5-millions-de-sites-en-danger","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/la-vulnerabilite-du-plugin-wordpress-litespeed-met-5-millions-de-sites-en-danger\/","title":{"rendered":"La vuln\u00e9rabilit\u00e9 du plugin WordPress LiteSpeed \u200b\u200bmet 5 millions de sites en danger"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">27 f\u00e9vrier 2024<\/span><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">R\u00e9daction<\/span><\/span><span class=\"p-tags\">Vuln\u00e9rabilit\u00e9 \/ S\u00e9curit\u00e9 du site Web<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" href=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/02\/La-vulnerabilite-du-plugin-WordPress-LiteSpeed-\u200b\u200bmet-5-millions-de.jpg\" style=\"clear: left; display: block; float: left; text-align: center;\"><\/a><\/div>\n<p>Une vuln\u00e9rabilit\u00e9 de s\u00e9curit\u00e9 a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9e dans le plugin LiteSpeed \u200b\u200bCache pour WordPress qui pourrait permettre \u00e0 des utilisateurs non authentifi\u00e9s d&#8217;\u00e9lever leurs privil\u00e8ges.<\/p>\n<p>Suivi comme <strong>CVE-2023-40000<\/strong>la vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e en octobre 2023 dans la version 5.7.0.1.<\/p>\n<p>&#8220;Ce plugin souffre de fichiers stock\u00e9s non authentifi\u00e9s sur l&#8217;ensemble du site [cross-site scripting] vuln\u00e9rabilit\u00e9 et pourrait permettre \u00e0 tout utilisateur non authentifi\u00e9 de voler des informations sensibles, dans ce cas, d&#8217;\u00e9lever ses privil\u00e8ges sur le site WordPress en effectuant une seule requ\u00eate HTTP&#8221;, Rafie Muhammad, chercheur chez Patchstack. <a rel=\"nofollow noopener\" href=\"https:\/\/patchstack.com\/articles\/xss-vulnerability-in-litespeed-cache-plugin-affecting-4-million-sites\/\" target=\"_blank\">dit<\/a>.<\/p>\n<p><a rel=\"nofollow noopener\" href=\"https:\/\/wordpress.org\/plugins\/litespeed-cache\/\" target=\"_blank\">Cache LiteSpeed<\/a>, qui sert \u00e0 am\u00e9liorer les performances des sites, compte plus de cinq millions d&#8217;installations.  La derni\u00e8re version du plugin en 6.1, sortie le 5 f\u00e9vrier 2024.<\/p>\n<div class=\"check_two clear bobbob\"><center class=\"cf\"><a rel=\"nofollow noopener\" href=\"https:\/\/thehackernews.uk\/delinea728\" target=\"_blank\" title=\"Cybersecurity\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"La cyber-s\u00e9curit\u00e9\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/02\/1708012425_568_Les-pirates-informatiques-russes-de-Turla-ciblent-les-ONG-polonaises.jpg\" width=\"727\" height=\"90\"\/><\/a><\/center><\/div>\n<p>La soci\u00e9t\u00e9 de s\u00e9curit\u00e9 WordPress a d\u00e9clar\u00e9 que CVE-2023-40000 est le r\u00e9sultat d&#8217;un manque de v\u00e9rification des entr\u00e9es des utilisateurs et <a rel=\"nofollow noopener\" href=\"https:\/\/developer.wordpress.org\/apis\/security\/escaping\/\" target=\"_blank\">sortie d&#8217;\u00e9chappement<\/a>.  La vuln\u00e9rabilit\u00e9 est enracin\u00e9e dans une fonction nomm\u00e9e update_cdn_status() et peut \u00eatre reproduite dans une installation par d\u00e9faut. <\/p>\n<p>&#8220;\u00c9tant donn\u00e9 que la charge utile XSS est plac\u00e9e en tant que notification d&#8217;administrateur et que la notification d&#8217;administrateur peut \u00eatre affich\u00e9e sur n&#8217;importe quel point de terminaison wp-admin, cette vuln\u00e9rabilit\u00e9 pourrait \u00e9galement \u00eatre facilement d\u00e9clench\u00e9e par tout utilisateur ayant acc\u00e8s \u00e0 la zone wp-admin&#8221;, a d\u00e9clar\u00e9 Muhammad.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a rel=\"nofollow\" href=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/02\/1709054664_118_La-vulnerabilite-du-plugin-WordPress-LiteSpeed-\u200b\u200bmet-5-millions-de.jpg\" style=\"clear: left; display: block; float: left; text-align: center;\"><img decoding=\"async\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2024\/02\/1709054664_118_La-vulnerabilite-du-plugin-WordPress-LiteSpeed-\u200b\u200bmet-5-millions-de.jpg\" alt=\"Plugin WordPress LiteSpeed\" border=\"0\" data-original-height=\"469\" data-original-width=\"728\" title=\"Plugin WordPress LiteSpeed\"\/><\/a><\/div>\n<p>La divulgation arrive quatre mois apr\u00e8s que Wordfence a r\u00e9v\u00e9l\u00e9 une autre faille XSS dans le m\u00eame plugin (CVE-2023-4372, score CVSS : 6,4) en raison d&#8217;une d\u00e9sinfection insuffisante des entr\u00e9es et d&#8217;un \u00e9chappement de sortie sur les attributs fournis par l&#8217;utilisateur.  Ce probl\u00e8me a \u00e9t\u00e9 r\u00e9solu dans la version 5.7.<\/p>\n<p>&#8220;Cela permet aux attaquants authentifi\u00e9s disposant d&#8217;autorisations de niveau contributeur et sup\u00e9rieures d&#8217;injecter des scripts Web arbitraires dans des pages qui s&#8217;ex\u00e9cuteront chaque fois qu&#8217;un utilisateur acc\u00e8de \u00e0 une page inject\u00e9e&#8221;, Istv\u00e1n M\u00e1rton <a rel=\"nofollow noopener\" href=\"https:\/\/www.wordfence.com\/blog\/2023\/10\/4-million-wordpress-sites-affected-by-stored-cross-site-scripting-vulnerability-in-lightspeed-cache-plugin\/\" target=\"_blank\">dit<\/a>.<\/p>\n<p><\/p>\n<div class=\"cf note-b\">Vous avez trouv\u00e9 cet article int\u00e9ressant ?  Suivez-nous sur <a rel=\"nofollow noopener\" href=\"https:\/\/twitter.com\/thehackersnews\" target=\"_blank\">Twitter <i class=\"icon-font icon-twitter\">\uf099<\/i><\/a>  et <a rel=\"nofollow noopener\" href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" target=\"_blank\">LinkedIn<\/a> pour lire plus de contenu exclusif que nous publions.<\/div>\n<\/div>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><br \/>\n<br \/><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2024\/02\/wordpress-litespeed-plugin.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\ue80227 f\u00e9vrier 2024\ue804R\u00e9dactionVuln\u00e9rabilit\u00e9 \/ S\u00e9curit\u00e9 du site Web Une vuln\u00e9rabilit\u00e9 de s\u00e9curit\u00e9 a \u00e9t\u00e9 r\u00e9v\u00e9l\u00e9e dans le plugin LiteSpeed \u200b\u200bCache pour WordPress qui pourrait permettre \u00e0 des utilisateurs non authentifi\u00e9s d&#8217;\u00e9lever leurs privil\u00e8ges. Suivi comme CVE-2023-40000la vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 corrig\u00e9e en octobre 2023 dans la version 5.7.0.1. &#8220;Ce plugin souffre de fichiers stock\u00e9s non authentifi\u00e9s [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1168923,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[200292,4168,4165,4161,200267,1572,4159,4171,232118,200271,4955,1610,200268,200269,200270,51599,128318,4172,4169,2783,4166,3667,4164,51600],"class_list":["post-1168922","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-actualites-sur-la-cybersecurite","tag-comment-pirater","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-cyberactualites","tag-danger","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-litespeed","tag-logiciel-malveillant-rancongiciel","tag-met","tag-millions","tag-mises-a-jour-sur-la-cybersecurite","tag-nouvelles-des-pirates","tag-nouvelles-sur-le-piratage","tag-plugin","tag-securite-des-informations","tag-securite-informatique","tag-securite-internet","tag-sites","tag-violation-de-donnees","tag-vulnerabilite","tag-vulnerabilite-logicielle","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1168922","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=1168922"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/1168922\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/1168923"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=1168922"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=1168922"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=1168922"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}