{"id":10447,"date":"2025-07-23T12:33:25","date_gmt":"2025-07-23T05:33:25","guid":{"rendered":"https:\/\/infosec.new88088.net\/?p=10447"},"modified":"2026-02-05T12:33:33","modified_gmt":"2026-02-05T05:33:33","slug":"tan-cong-sharepoint-quy-mo-lon-lo-dien-chuoi-loi-cho-phep-rce-va-bypass-xac-thuc","status":"publish","type":"post","link":"https:\/\/infosec.new88088.net\/2025\/07\/23\/tan-cong-sharepoint-quy-mo-lon-lo-dien-chuoi-loi-cho-phep-rce-va-bypass-xac-thuc\/","title":{"rendered":"T\u1ea5n c\u00f4ng SharePoint quy m\u00f4 l\u1edbn: L\u1ed9 di\u1ec7n chu\u1ed7i l\u1ed7i cho ph\u00e9p RCE v\u00e0 bypass x\u00e1c th\u1ef1c"},"content":{"rendered":"<p><b>Microsoft v\u1eeba ph\u00e1t c\u1ea3nh b\u00e1o b\u1ea3o m\u1eadt kh\u1ea9n c\u1ea5p sau khi ph\u00e1t hi\u1ec7n chi\u1ebfn d\u1ecbch t\u1ea5n c\u00f4ng c\u00f3 ch\u1ee7 \u0111\u00edch nh\u1eafm v\u00e0o h\u1ec7 th\u1ed1ng SharePoint Server on-premises, b\u1eaft \u0111\u1ea7u t\u1eeb ng\u00e0y 7\/7\/2025. Ba nh\u00f3m tin t\u1eb7c Trung Qu\u1ed1c g\u1ed3m Linen Typhoon, Violet Typhoon v\u00e0 Storm-2603 b\u1ecb x\u00e1c \u0111\u1ecbnh \u0111\u1ee9ng sau ho\u1ea1t \u0111\u1ed9ng khai th\u00e1c. C\u00e1c cu\u1ed9c t\u1ea5n c\u00f4ng t\u1eadn d\u1ee5ng chu\u1ed7i l\u1ed7 h\u1ed5ng nghi\u00eam tr\u1ecdng cho ph\u00e9p v\u01b0\u1ee3t qua x\u00e1c th\u1ef1c, th\u1ef1c thi m\u00e3 t\u1eeb xa v\u00e0 chi\u1ebfm quy\u1ec1n ki\u1ec3m so\u00e1t h\u1ec7 th\u1ed1ng n\u1ed9i b\u1ed9.<\/b><\/p>\n<div style=\"text-align: center\">\n<div class=\"bbImageWrapper  js-lbImage\" title=\"SharePoint.png\" data-src=\"https:\/\/whitehat.vn\/attachments\/sharepoint-png.17361\/\" data-lb-sidebar-href=\"\" data-lb-caption-extra-html=\"\" data-single-image=\"1\"><img fetchpriority=\"high\" decoding=\"async\" class=\"bbImage\" title=\"SharePoint.png\" src=\"https:\/\/whitehat.vn\/attachments\/sharepoint-png.17361\/\" alt=\"SharePoint.png\" width=\"700\" height=\"390\" data-url=\"\" data-zoom-target=\"1\" \/><\/div>\n<\/div>\n<p>\u0110\u1eb7c bi\u1ec7t, ng\u00e0y 18\/7\/2025, m\u1ed9t trong nh\u1eefng n\u1ea1n nh\u00e2n b\u1ecb x\u00e2m nh\u1eadp \u0111\u01b0\u1ee3c x\u00e1c nh\u1eadn l\u00e0 C\u01a1 quan An ninh H\u1ea1t nh\u00e2n Qu\u1ed1c gia (NNSA), thu\u1ed9c B\u1ed9 N\u0103ng l\u01b0\u1ee3ng Hoa K\u1ef3. D\u00f9 ch\u1ec9 m\u1ed9t s\u1ed1 h\u1ec7 th\u1ed1ng b\u1ecb \u1ea3nh h\u01b0\u1edfng v\u00e0 ch\u01b0a ph\u00e1t hi\u1ec7n r\u00f2 r\u1ec9 d\u1eef li\u1ec7u m\u1eadt, v\u1ee5 vi\u1ec7c cho th\u1ea5y quy m\u00f4 v\u00e0 m\u1ee9c \u0111\u1ed9 tinh vi c\u1ee7a l\u00e0n s\u00f3ng t\u1ea5n c\u00f4ng. Microsoft 365 v\u00e0 c\u00e1c h\u1ec7 th\u1ed1ng ph\u00f2ng th\u1ee7 m\u1ea1ng ti\u00ean ti\u1ebfn \u0111\u00e3 gi\u00fap h\u1ea1n ch\u1ebf thi\u1ec7t h\u1ea1i, song th\u00f4ng tin n\u00e0y \u0111\u00e3 khi\u1ebfn c\u1ed9ng \u0111\u1ed3ng an ninh m\u1ea1ng M\u1ef9 \u0111\u1eb7c bi\u1ec7t c\u1ea3nh gi\u00e1c.<\/p>\n<p>B\u1ed1n l\u1ed7 h\u1ed5ng \u0111\u01b0\u1ee3c khai th\u00e1c trong \u0111\u1ee3t t\u1ea5n c\u00f4ng g\u1ed3m:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">CVE-2025-49706 (spoofing): cho ph\u00e9p k\u1ebb t\u1ea5n c\u00f4ng gi\u1ea3 m\u1ea1o danh t\u00ednh ng\u01b0\u1eddi d\u00f9ng h\u1ee3p ph\u00e1p trong qu\u00e1 tr\u00ecnh x\u00e1c th\u1ef1c<\/li>\n<li data-xf-list-type=\"ul\">CVE-2025-49704 (remote code execution): cho ph\u00e9p th\u1ef1c thi m\u00e3 t\u1eeb xa tr\u00ean m\u00e1y ch\u1ee7 SharePoint m\u1ee5c ti\u00eau<\/li>\n<li data-xf-list-type=\"ul\">CVE-2025-53770 (ToolShell Auth Bypass v\u00e0 RCE): cho ph\u00e9p truy c\u1eadp tr\u00e1i ph\u00e9p v\u00e0o m\u00f4i tr\u01b0\u1eddng d\u00f2ng l\u1ec7nh ToolShell v\u00e0 th\u1ef1c thi m\u00e3 \u0111\u1ed9c m\u00e0 kh\u00f4ng c\u1ea7n x\u00e1c th\u1ef1c<\/li>\n<li data-xf-list-type=\"ul\">CVE-2025-53771 (ToolShell Path Traversal): cho ph\u00e9p truy c\u1eadp v\u00e0 ch\u1ec9nh s\u1eeda c\u00e1c t\u1eadp tin nh\u1ea1y c\u1ea3m tr\u00ean h\u1ec7 th\u1ed1ng b\u1eb1ng c\u00e1ch v\u01b0\u1ee3t qua gi\u1edbi h\u1ea1n th\u01b0 m\u1ee5c th\u00f4ng th\u01b0\u1eddng<\/li>\n<\/ul>\n<p>Nh\u1eefng l\u1ed7 h\u1ed5ng n\u00e0y \u1ea3nh h\u01b0\u1edfng \u0111\u1ebfn c\u00e1c phi\u00ean b\u1ea3n SharePoint Server 2016, 2019 v\u00e0 Subscription Edition c\u00e0i \u0111\u1eb7t t\u1ea1i ch\u1ed7. SharePoint Online kh\u00f4ng b\u1ecb \u1ea3nh h\u01b0\u1edfng.<\/p>\n<p>Microsoft ghi nh\u1eadn k\u1ebb t\u1ea5n c\u00f4ng g\u1eedi c\u00e1c y\u00eau c\u1ea7u POST t\u1edbi endpoint ToolPane \u0111\u1ec3 trinh s\u00e1t, sau \u0111\u00f3 t\u1ea3i l\u00ean web shell \u0111\u1ed9c h\u1ea1i nh\u01b0 spinstall.aspx, spinstall0.aspx, spinstall1.aspx v\u00e0 spinstall2.aspx. C\u00e1c shell n\u00e0y ch\u1ee9a l\u1ec7nh thu th\u1eadp d\u1eef li\u1ec7u MachineKey th\u00f4ng qua GET, cho ph\u00e9p \u0111\u00e1nh c\u1eafp th\u00f4ng tin x\u00e1c th\u1ef1c ASP.NET nh\u1eb1m m\u1edf r\u1ed9ng ph\u1ea1m vi ki\u1ec3m so\u00e1t h\u1ec7 th\u1ed1ng.<\/p>\n<p>Trong s\u1ed1 c\u00e1c l\u1ed7 h\u1ed5ng, CVE-2025-53771 thu\u1ed9c lo\u1ea1i x\u00e1c th\u1ef1c sai (CWE-287) cho ph\u00e9p c\u00e1c t\u00e0i kho\u1ea3n \u0111\u00e3 x\u00e1c th\u1ef1c th\u1ef1c hi\u1ec7n spoofing trong m\u00f4i tr\u01b0\u1eddng m\u1ea1ng n\u1ed9i b\u1ed9. \u0110\u00e1ng ch\u00fa \u00fd, l\u1ed7 h\u1ed5ng n\u00e0y c\u00f3 th\u1ec3 \u0111\u01b0\u1ee3c li\u00ean k\u1ebft v\u1edbi CVE-2025-49704 \u0111\u1ec3 t\u1ea1o th\u00e0nh chu\u1ed7i t\u1ea5n c\u00f4ng ph\u1ee9c t\u1ea1p, t\u1eeb \u0111\u00f3 chi\u1ebfm quy\u1ec1n \u0111i\u1ec1u khi\u1ec3n h\u1ec7 th\u1ed1ng \u1edf m\u1ee9c s\u00e2u h\u01a1n v\u00e0 duy tr\u00ec truy c\u1eadp l\u00e2u d\u00e0i. B\u1ec1 m\u1eb7t t\u1ea5n c\u00f4ng khi c\u00e1c l\u1ed7 h\u1ed5ng \u0111\u01b0\u1ee3c k\u1ebft h\u1ee3p ng\u00e0y c\u00e0ng ph\u1ee9c t\u1ea1p v\u00e0 kh\u00f3 ph\u00e1t hi\u1ec7n, t\u1ea1o r\u1ee7i ro nghi\u00eam tr\u1ecdng cho c\u00e1c t\u1ed5 ch\u1ee9c doanh nghi\u1ec7p.<\/p>\n<p>Tr\u01b0\u1edbc m\u1ee9c \u0111\u1ed9 nghi\u00eam tr\u1ecdng v\u00e0 kh\u1ea3 n\u0103ng lan r\u1ed9ng c\u1ee7a chu\u1ed7i t\u1ea5n c\u00f4ng, Microsoft \u0111\u00e3 nhanh ch\u00f3ng ph\u00e1t h\u00e0nh c\u00e1c b\u1ea3n v\u00e1 b\u1ea3o m\u1eadt t\u01b0\u01a1ng \u1ee9ng nh\u1eb1m ng\u0103n ch\u1eb7n nguy c\u01a1 b\u1ecb khai th\u00e1c trong th\u1ef1c t\u1ebf:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">KB5002768 cho SharePoint Server Subscription Edition<\/li>\n<li data-xf-list-type=\"ul\">KB5002754 v\u00e0 KB5002753 cho SharePoint Server 2019<\/li>\n<li data-xf-list-type=\"ul\">KB5002760 v\u00e0 KB5002759 cho SharePoint Server 2016<\/li>\n<\/ul>\n<p>\u0110\u00e1ng ch\u00fa \u00fd, b\u1ea3n c\u1eadp nh\u1eadt cho CVE-2025-53771 c\u00f2n n\u00e2ng c\u1ea5p c\u00e1c l\u1edbp ph\u00f2ng th\u1ee7, bao g\u1ed3m c\u1ea3i ti\u1ebfn c\u01a1 ch\u1ebf x\u00e1c th\u1ef1c v\u00e0 gia c\u1ed1 giao th\u1ee9c truy\u1ec1n th\u00f4ng m\u1ea1ng nh\u1eb1m ch\u1eb7n \u0111\u1ee9ng c\u00e1c n\u1ed7 l\u1ef1c spoofing t\u1eeb n\u1ed9i b\u1ed9.<\/p>\n<p>\u0110\u1ec3 b\u1ea3o v\u1ec7 h\u1ec7 th\u1ed1ng tr\u01b0\u1edbc l\u00e0n s\u00f3ng t\u1ea5n c\u00f4ng n\u00e0y, Microsoft khuy\u1ebfn ngh\u1ecb c\u00e1c t\u1ed5 ch\u1ee9c tri\u1ec3n khai ngay c\u00e1c bi\u1ec7n ph\u00e1p ph\u00f2ng th\u1ee7 sau:<\/p>\n<ul>\n<li data-xf-list-type=\"ul\">K\u00edch ho\u1ea1t AMSI \u1edf ch\u1ebf \u0111\u1ed9 Full Mode \u0111\u1ec3 ph\u00e1t hi\u1ec7n m\u00e3 \u0111\u1ed9c \u1ea9n s\u00e2u trong ti\u1ebfn tr\u00ecnh m\u00e1y ch\u1ee7 v\u00e0 ng\u0103n ch\u1eb7n t\u1eeb s\u1edbm c\u00e1c h\u00e0nh vi th\u1ef1c thi tr\u00e1i ph\u00e9p<\/li>\n<li data-xf-list-type=\"ul\">Trang b\u1ecb Microsoft Defender Antivirus v\u00e0 \u0111\u1ea3m b\u1ea3o c\u1eadp nh\u1eadt \u0111\u1ecbnh k\u1ef3, gi\u00fap nh\u1eadn di\u1ec7n v\u00e0 lo\u1ea1i b\u1ecf c\u00e1c web shell nh\u01b0 spinstall.aspx m\u00e0 tin t\u1eb7c \u0111ang s\u1eed d\u1ee5ng<\/li>\n<li data-xf-list-type=\"ul\">Xoay v\u00f2ng kh\u00f3a x\u00e1c th\u1ef1c ASP.NET (machine key) \u0111\u1ec3 v\u00f4 hi\u1ec7u h\u00f3a quy\u1ec1n truy c\u1eadp m\u00e0 k\u1ebb t\u1ea5n c\u00f4ng c\u00f3 th\u1ec3 \u0111\u00e3 gi\u00e0nh \u0111\u01b0\u1ee3c b\u1eb1ng c\u00e1ch \u0111\u00e1nh c\u1eafp kh\u00f3a c\u0169<\/li>\n<li data-xf-list-type=\"ul\">Kh\u1edfi \u0111\u1ed9ng l\u1ea1i d\u1ecbch v\u1ee5 IIS b\u1eb1ng l\u1ec7nh iisreset.exe nh\u1eb1m \u00e1p d\u1ee5ng c\u00e1c thay \u0111\u1ed5i b\u1ea3o m\u1eadt v\u00e0 lo\u1ea1i b\u1ecf phi\u00ean l\u00e0m vi\u1ec7c \u0111\u1ed9c h\u1ea1i c\u00f2n t\u1ed3n t\u1ea1i trong b\u1ed9 nh\u1edb<\/li>\n<\/ul>\n<p>CISA \u0111\u00e3 th\u00eam CVE-2025-53771 v\u00e0o danh s\u00e1ch c\u1ea7n kh\u1eafc ph\u1ee5c kh\u1ea9n c\u1ea5p ng\u00e0y 22\/7\/2025, v\u1edbi h\u1ea1n ch\u00f3t th\u1ef1c hi\u1ec7n ch\u1ec9 sau \u0111\u00f3 m\u1ed9t ng\u00e0y. Khung th\u1eddi gian 24 gi\u1edd ph\u1ea3n \u00e1nh m\u1ee9c \u0111\u1ed9 nghi\u00eam tr\u1ecdng \u0111\u1eb7c bi\u1ec7t c\u1ee7a l\u1ed7 h\u1ed5ng. C\u01a1 quan n\u00e0y c\u0169ng nh\u1ea5n m\u1ea1nh y\u00eau c\u1ea7u ng\u1eaft k\u1ebft n\u1ed1i to\u00e0n b\u1ed9 m\u00e1y ch\u1ee7 SharePoint public-facing \u0111\u00e3 h\u1ebft v\u00f2ng \u0111\u1eddi (EOL) ho\u1eb7c ng\u1eebng h\u1ed7 tr\u1ee3 (EOS). C\u00e1c h\u1ec7 th\u1ed1ng nh\u01b0 SharePoint 2013 tr\u1edf v\u1ec1 tr\u01b0\u1edbc kh\u00f4ng c\u00f2n nh\u1eadn b\u1ea3n v\u00e1 v\u00e0 ph\u1ea3i b\u1ecb lo\u1ea1i b\u1ecf kh\u1ecfi h\u1ea1 t\u1ea7ng v\u1eadn h\u00e0nh ch\u00ednh th\u1ee9c.<\/p>\n<p>Theo c\u00e1c chuy\u00ean gia WhiteHat: <i>&#8220;D\u00f9 ch\u01b0a ghi nh\u1eadn d\u1ea5u hi\u1ec7u ransomware khai th\u00e1c tr\u1ef1c ti\u1ebfp chu\u1ed7i l\u1ed7 h\u1ed5ng n\u00e0y, nh\u01b0ng vi\u1ec7c k\u1ebft h\u1ee3p gi\u1eefa bypass x\u00e1c th\u1ef1c v\u00e0 th\u1ef1c thi m\u00e3 t\u1eeb xa l\u00e0 c\u00f4ng th\u1ee9c l\u00fd t\u01b0\u1edfng cho c\u00e1c chi\u1ebfn d\u1ecbch t\u1ea5n c\u00f4ng m\u00e3 h\u00f3a d\u1eef li\u1ec7u. Ch\u00fang t\u00f4i nh\u1eadn \u0111\u1ecbnh m\u1ee9c \u0111\u1ed9 r\u1ee7i ro l\u00e0 r\u1ea5t cao, kh\u00f4ng ch\u1ec9 v\u00ec ph\u1ea1m vi \u1ea3nh h\u01b0\u1edfng m\u00e0 c\u00f2n v\u00ec t\u1ed1c \u0111\u1ed9 khai th\u00e1c t\u0103ng m\u1ea1nh. M\u1ed9t khi c\u00f4ng c\u1ee5 khai th\u00e1c b\u1ecb chia s\u1ebb c\u00f4ng khai, m\u1ecdi h\u1ec7 th\u1ed1ng ch\u01b0a v\u00e1 s\u1ebd tr\u1edf th\u00e0nh \u2018mi\u1ebfng m\u1ed3i b\u00e9o b\u1edf\u2019. C\u00e0ng ch\u1eadm c\u1eadp nh\u1eadt, nguy c\u01a1 b\u1ecb t\u1ea5n c\u00f4ng c\u00e0ng c\u1eadn k\u1ec1.&#8221;<\/i><\/p>\n<p>Microsoft \u0111\u00e1nh gi\u00e1: c\u00e1c nh\u00f3m t\u1ea5n c\u00f4ng APT s\u1ebd s\u1edbm t\u00edch h\u1ee3p chu\u1ed7i l\u1ed7 h\u1ed5ng n\u00e0y v\u00e0o b\u1ed9 c\u00f4ng c\u1ee5 t\u1ea5n c\u00f4ng c\u1ee7a m\u00ecnh, nguy c\u01a1 lan r\u1ed9ng l\u00e0 r\u00f5 r\u00e0ng, \u0111\u1eb7c bi\u1ec7t v\u1edbi nh\u1eefng t\u1ed5 ch\u1ee9c ch\u01b0a k\u1ecbp v\u00e1 h\u1ec7 th\u1ed1ng. Chuy\u00ean gia WhiteHat c\u1ea3nh b\u00e1o: <i>\u201cKh\u00f4ng h\u00e0nh \u0111\u1ed9ng ngay l\u00fac n\u00e0y ch\u1eb3ng kh\u00e1c n\u00e0o m\u1eddi k\u1ebb t\u1ea5n c\u00f4ng v\u00e0o th\u1eb3ng trung t\u00e2m d\u1eef li\u1ec7u. L\u00fac \u0111\u00f3, kh\u00f4ng ch\u1ec9 l\u00e0 web shell, m\u00e0 c\u00f3 th\u1ec3 l\u00e0 c\u1ea3 m\u1ed9t chi\u1ebfn d\u1ecbch m\u00e3 h\u00f3a, \u0111\u00f2i chu\u1ed9c v\u00e0 \u0111\u00e1nh c\u1eafp d\u1eef li\u1ec7u \u1edf c\u1ea5p \u0111\u1ed9 s\u00e2u h\u01a1n.<\/i>\u201d<\/p>\n<p>Vi\u1ec7c c\u1eadp nh\u1eadt b\u1ea3n v\u00e1 kh\u00f4ng c\u00f2n l\u00e0 l\u1ef1a ch\u1ecdn, \u0111\u00f3 l\u00e0 h\u00e0nh \u0111\u1ed9ng s\u1ed1ng c\u00f2n trong b\u1ed1i c\u1ea3nh k\u1ebb t\u1ea5n c\u00f4ng \u0111\u00e3 c\u00f3 s\u1eb5n \u0111\u01b0\u1eddng \u0111i, ch\u1ec9 ch\u1edd th\u1eddi c\u01a1 \u0111\u1ec3 b\u01b0\u1edbc v\u00e0o.<\/p>\n<div style=\"text-align: right\"><b><i>WhiteHat t\u1ed5ng h\u1ee3p<\/i><\/b>\u200b<\/div>\n<div style=\"text-align: right;margin-top: 16px\"><i>Theo: <a href=\"https:\/\/whitehat.vn\/threads\/tan-cong-sharepoint-quy-mo-lon-lo-dien-chuoi-loi-cho-phep-rce-va-bypass-xac-thuc.18595\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/whitehat.vn\/threads\/tan-cong-sharepoint-quy-mo-lon-lo-dien-chuoi-loi-cho-phep-rce-va-bypass-xac-thuc.18595\/<\/a><\/i><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft v\u1eeba ph\u00e1t c\u1ea3nh b\u00e1o b\u1ea3o m\u1eadt kh\u1ea9n c\u1ea5p sau khi ph\u00e1t hi\u1ec7n chi\u1ebfn d\u1ecbch t\u1ea5n c\u00f4ng c\u00f3 ch\u1ee7 \u0111\u00edch nh\u1eafm v\u00e0o h\u1ec7 th\u1ed1ng SharePoint Server on-premises, b\u1eaft \u0111\u1ea7u t\u1eeb ng\u00e0y 7\/7\/2025. Ba nh\u00f3m tin t\u1eb7c Trung Qu\u1ed1c g\u1ed3m Linen Typhoon, Violet Typhoon v\u00e0 Storm-2603 b\u1ecb x\u00e1c \u0111\u1ecbnh \u0111\u1ee9ng sau ho\u1ea1t \u0111\u1ed9ng khai th\u00e1c. C\u00e1c [&hellip;]<\/p>\n","protected":false},"author":46,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[33],"tags":[],"class_list":["post-10447","post","type-post","status-publish","format-standard","hentry","category-tin-tuc-cua-vien"],"_links":{"self":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10447","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/users\/46"}],"replies":[{"embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/comments?post=10447"}],"version-history":[{"count":0,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/posts\/10447\/revisions"}],"wp:attachment":[{"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/media?parent=10447"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/categories?post=10447"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/infosec.new88088.net\/wp-json\/wp\/v2\/tags?post=10447"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}