孚盟云CRM AjaxAttachment.ashx SQL注入漏洞


漏洞简介

上海孚盟软件有限公司是一家专业的外贸SaaS服务和行业解决方案提供商。其旗下产品孚盟云AjaxAttachment.ashx接口存在SQL注入漏洞,未经身份验证的远程攻击者除了可以利用 SQL注入漏洞获取数据库中的信息(例如,管理员后台密码、站点的用户个人信息)之外,甚至在高权限的情况可向服务器中写入木马,进一步获取服务器系统权限。

影响版本

fofa语法

app="孚盟软件-孚盟云"

漏洞分析

直接看 AjaxAttachment.ashx 对应的dll文件 FumaCRM_BS.NewWeb.dll 里有关 AjaxAttachment 方法的实现如下

public void ProcessRequest(HttpContext context)
{
  context.Response.ContentType = "text/plain";
  string str1 = context.Request["method"].ToString();
  if (!string.IsNullOrEmpty(UserCookie.GetCookieValue("empId")))
  {
    this.empID = UserCookie.GetCookieValue("empId");
    this.empID = FumaCRM_BS.Utility.Encrypt.Encrypt.DesDecrypt(this.empID);
  }
  string str2 = str1;
  if (!string.op_Equality(str2, "AddMouldAttachFile"))
  {
    if (!string.op_Equality(str2, "saveAttach"))
    {
      if (!string.op_Equality(str2, "uploadFileToOss"))
        return;
      this.uploadFileToOss(context);
    }
    else
      this.saveAttach(context);
  }
  else
    this.AddMouldAttachFile(context);
}

当 method=saveAttach 时,进入saveAttach方法

private void saveAttach(HttpContext context)
{
  Helper.WriteLog("savePriceAttach进入方法", "products");
  try
  {
    UserCookie.GetCookieValue("corpId");
    string str1 = context.Request["FUIDs"] == null ? "" : context.Request["FUIDs"].ToString();
    string SQLString = $"SELECT A.*,B.DocExtDescrip AS FileTypeName,C.CNEmpName AS OwnerName,\n          D.CNEmpName AS KeyInName,E.CNEmpName AS NearEditEmpName \n          FROM dcFileMouldRelation F \n          JOIN dcFile A(nolock) ON F.FileFUID = A.FUID \n          LEFT JOIN dcDocType B(nolock) ON upper(A.FileType)=upper(B.DocExtSign) \n          LEFT JOIN bfEMP C(nolock) ON A.OwnerID=C.EmpID \n          LEFT JOIN bfEMP D(nolock) ON A.KeyInID=D.EmpID \n          LEFT JOIN bfEMP E(nolock) ON A.NearEditEmpID=E.EmpID \n          WHERE F.MouldID = '{(context.Request["MouldID"].ToString() == null ? "BF001" : context.Request["MouldID"].ToString())}'  and  A.FUID='{str1}'";
    if (((InternalDataCollectionBase) this.dbHelper.Query(SQLString).Tables[0].Rows).Count <= 0)

未经过滤或参数化绑定的参数 MouldID 被直接拼接进SQL语句中进行执行,造成SQL注入漏洞。

漏洞复现

GET /m/Dingding/Ajax/AjaxAttachment.ashx?method=saveAttach&MouldID=SQLI_POC HTTP/1.1
Host: fumacrm.mrxn.net

通过报错注入 成功在响应回显数据版本信息


手机扫码阅读

索贝融媒体 /sobey-mchEditor/mch/Jzt/statistics/ 多个SQL注入漏洞

索贝融媒体 /sobey-mchEditor/mch/Jzt/statistics/countJztArticleGroupByChannel2 SQL注入漏洞

评 论