Horizon Alert
Summary of the vulnerability and why it matters
Multiple Supsystic Pro plugins were compromised through their update server, allowing attackers to inject malicious code that can steal sensitive data and take over affected websites. This issue is significant because it impacts internet-facing web applications, making them accessible from the public internet. The primary concern is to confirm if these plugins are in use and assess potential exposure.
- Malicious code in plugin updates.
- Steals data, grants site control.
- Confirm usage, assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker could exploit this vulnerability by leveraging a compromised update server that distributed malicious code within Supsystic Pro plugins. This would allow an unauthenticated attacker to deploy a secondary payload. The vulnerability can lead to the exfiltration of sensitive data and full site control.
- No authentication required.
- Malicious code deployed via update server.
- Sensitive data exfiltration and site control.
Live Threat
Current exploitation, exposure, and threat context
When Supsystic Pro plugins are distributed via a compromised update server, unauthenticated attackers could deploy a second-stage payload. This payload may exfiltrate credentials and other sensitive data, and grant full control of affected websites.
- Website credentials and sensitive data.
- Via compromised update server distribution.
- Full site control and data exfiltration.
Operational Fix
Recommended remediation, mitigation, and detection steps
Attackers can deploy a second-stage payload to exfiltrate credentials and gain full control of sites due to malicious code in Supsystic Pro plugins distributed via a compromised update server. The first practical move is to identify all instances of these plugins, confirm their reachability and business criticality, and then locate the accountable owner to plan remediation based on risk.
- Site owners should own this issue.
- Verify plugin installation and exposure.
- Plan remediation based on site risk.