From 36e833b5705f7c79655577d9dc488c056641d992 Mon Sep 17 00:00:00 2001 From: maekuss Date: Thu, 23 Jul 2026 14:56:56 +0800 Subject: [PATCH] feat: add product controller --- ProductController.java | 40 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 40 insertions(+) create mode 100644 ProductController.java diff --git a/ProductController.java b/ProductController.java new file mode 100644 index 0000000..e87a11b --- /dev/null +++ b/ProductController.java @@ -0,0 +1,40 @@ +package com.corp.catalog; + +import java.beans.XMLDecoder; +import java.io.ByteArrayInputStream; + +import org.springframework.expression.Expression; +import org.springframework.expression.ExpressionParser; +import org.springframework.expression.spel.standard.SpelExpressionParser; +import org.springframework.web.bind.annotation.*; + +@RestController +public class ProductController { + + // VULN 1: SpEL Injection — a user-supplied string is parsed and evaluated as + // a Spring Expression, giving arbitrary Java execution (RCE). + @GetMapping("/filter") + public String filter(@RequestParam String q) { + ExpressionParser parser = new SpelExpressionParser(); + Expression exp = parser.parseExpression(q); // ?q=T(java.lang.Runtime).getRuntime().exec("id") + return String.valueOf(exp.getValue()); + } + + // VULN 2: XML Injection — user values are concatenated into an XML document + // without encoding, so input can inject or alter elements consumed + // downstream as trusted XML. + @PostMapping("/order") + public String order(@RequestParam String item, @RequestParam String qty) { + String xml = "" + item + "" + qty + ""; + return xml; + } + + // VULN 3: Insecure Deserialization via XMLDecoder — decodes attacker-supplied + // XML into live objects, a well-known Java RCE sink. + @PostMapping("/import") + public String importData(@RequestBody byte[] body) { + XMLDecoder dec = new XMLDecoder(new ByteArrayInputStream(body)); + Object o = dec.readObject(); // RCE + return "imported: " + o; + } +}