
Hay una vulnerabilidad de inyección SQL en el backend de Ruoyi v4.8.3
filterKeyword para Inyección SQLSe requiere autorización / Solo pruebas autorizadas
Este repositorio está destinado únicamente a la investigación de seguridad y las pruebas autorizadas. No lo utilice contra sistemas sin permiso explícito.
Este repositorio es solo para investigación de seguridad y pruebas autorizadas explícitamente. No lo utilice en sistemas no autorizados.
El endpoint /tool/gen/createTable del módulo de generación de código de RuoYi v4.8.3 permite a los usuarios autenticados enviar SQL para crear tablas. El endpoint llama a SqlUtil.filterKeyword() para filtrar palabras clave peligrosas. Sin embargo, la implementación elimina todos los espacios en blanco de la entrada antes de verificar las entradas de la lista negra que contienen espacios al final, como select , insert y drop . Por lo tanto, esas entradas no pueden coincidir con la entrada normalizada.
Una declaración CREATE TABLE ... AS SELECT ... (CTAS) puede pasar la verificación de tipo MySqlCreateTableStatement de Druid mientras aún ejecuta un SELECT. Un atacante con una sesión válida de backend puede utilizar este comportamiento para realizar inyección SQL ciega basada en booleanos, extraer datos sensibles y crear tablas.
JSESSIONID válido.El script de verificación utiliza la siguiente lógica para extraer el hash de la contraseña y el salt del usuario admin de la tabla sys_user:
login_name, password y salt mediante CTAS.SUBSTRING() en el WHERE./tool/gen/list.requests, urllib3Instalar dependencias:
python -m pip install requests urllib3
Abra exp.py y reemplace las siguientes dos líneas en la sección de configuración cerca de la parte superior del archivo:
TARGET = "http://127.0.0.1:8080"
COOKIE = "JSESSIONID=your_session_id"
Donde:
TARGET: la URL base de RuoYi a probar, por ejemplo http://127.0.0.1:8080.COOKIE: una sesión JSESSIONID de backend autenticada válida.Después de reemplazar la URL y la sesión, ejecute:
python exp.py
El script crea una tabla intermedia y muchas tablas de prueba booleanas en la base de datos objetivo. Úselo solo en un entorno aislado o explícitamente autorizado, y haga que el administrador de la base de datos elimine las tablas generadas después de las pruebas.
exp.png muestra una verificación exitosa en un entorno local autorizado:

filterKeyword(), pero no la trate como el único control de seguridad.The /tool/gen/createTable endpoint in the code-generation module of RuoYi v4.8.3 accepts table-creation SQL from authenticated backend users. The endpoint calls SqlUtil.filterKeyword() to block dangerous SQL keywords. However, the implementation removes all whitespace from the input before checking blacklist entries that contain trailing spaces, such as select , insert , and drop . Those entries therefore cannot match the normalized input.
A CREATE TABLE ... AS SELECT ... (CTAS) statement can pass the Druid MySqlCreateTableStatement type check while still executing a SELECT. An attacker with a valid backend session may use this behavior for boolean-based blind SQL injection, sensitive-data extraction, and table creation.
JSESSIONID.The script recovers the admin password hash and salt from sys_user using the following oracle:
login_name, password, and salt.SUBSTRING() condition./tool/gen/list.requests, urllib3Install dependencies:
python -m pip install requests urllib3
Open exp.py and replace the following two lines in the configuration section near the top of the file:
TARGET = "http://127.0.0.1:8080"
COOKIE = "JSESSIONID=your_session_id"
Where:
TARGET is the RuoYi base URL to test, for example http://127.0.0.1:8080.COOKIE is a valid authenticated backend JSESSIONID session.After replacing the URL and session, run:
python exp.py
The script creates an intermediate table and many boolean-test tables in the target database. Use it only in an isolated or explicitly authorized environment, and have the database administrator remove the generated tables after testing.
exp.png shows a successful verification in an authorized local environment:

filterKeyword(), but do not treat it as the sole security control.