Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2024-57521-RuoYi-SQLi — Static code audit of CVE-2024-57521, an authenticated SQL injection in RuoYi-Vue's generator module, with source-to-sink analysis and a %0b filter bypass PoC. | Kitploit
도구/GitHubGitHub/xs2024770/cve-2024-57521-ruoyi-sqli
Static Code Analysis (SAST)Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPapers & ResearchLearning & Education
GitHub

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
xs2024770/cve-2024-57521-ruoyi-sqli

CVE-2024-57521-RuoYi-SQLi

Static code audit of CVE-2024-57521, an authenticated SQL injection in RuoYi-Vue's generator module, with source-to-sink analysis and a %0b filter bypass PoC.

저장소 보기
2110일 전아직 검토되지 않음
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

🛡️ CVE-2024-57521 RuoYi-Vue Post-Authentication SQL Injection Vulnerability Audit Notes

CVE

Figure 1: CVE-2024-57521 SQL Injection Vulnerability Data Flow Audit Diagram

0. Project Statement

This repository is intended for security research and educational purposes only. Do not use the techniques in this document for unauthorized attacks. All tests were completed in a local static code audit environment.


1. Vulnerability Overview

  • CVE ID: CVE-2024-57521
  • Affected Component: RuoYi-Vue Permission Management System (ruoyi-generator module)
  • Affected Versions: <= v4.7.9
  • Vulnerability Type: Post-Authentication SQL Injection (Boolean Blind Injection / CWE-89)
  • CVSS Score: 10.0 (Critical)
  • Audit Method: Pure Static Code Audit (Source Code Analysis)

2. Data Flow Audit Analysis (Source → Filter → Sink)

2.1 Source (User Input Entry Point)

  • File Location: ruoyi-generator/src/main/java/com/ruoyi/generator/controller/GenController.java

Key Code:

@PostMapping("/createTable")
public AjaxResult createTableSave(@RequestParam("sql") String sql, @RequestParam("tplWebType") String tplWebType)
{
    try
    {
        SqlUtil.filterKeyword(sql); // Calls the filter before entering business logic

Analysis: A backend administrator can pass arbitrary database table creation statements through the sql parameter of an HTTP POST request. The entry point does not sufficiently restrict user input and directly hands it off to the subsequent filter for processing.

Screenshot Evidence: 03-SqlUtil-filterKeyword

2.2 Filter (Fatal Flaw in the Filter)

· File Location: ruoyi-common/src/main/java/com/ruoyi/common/utils/sql/SqlUtil.java

Core Flawed Code:

// Line 16: Blacklist definition, note the keywords have [trailing spaces]
public static String SQL_REGEX = "\u0008|%0A|and |extractvalue|updatexml|sleep|information_schema|exec...";

// Lines 61-66: Filtering logic
String normalizedValue = value.replaceAll("\\p{Z}|\\s", ""); // First clears all spaces from the input
String[] sqlKeywords = StringUtils.split(SQL_REGEX, "\\|");
for (String sqlKeyword : sqlKeywords)
{
    if (StringUtils.indexOfIgnoreCase(normalizedValue, sqlKeyword) > -1)
    {
        throw new UtilException("Request parameter contains sensitive keyword " + sqlKeyword + ", potential security risk");
    }
}

Flaw Analysis: The filter first executes replaceAll("\\p{Z}|\\s", "") to remove all whitespace characters from the input. However, the keywords in the blacklist SQL_REGEX (such as "and ", "select ") have trailing spaces. This causes matching to inevitably fail. As long as the attacker uses %0b (vertical tab) instead of a space after the keyword, the blacklist check can be perfectly bypassed.

Screenshot Evidence:

02-SqlUtil-SQL_REGEX 01-GenController-createTableSave

2.3 Sink (Dangerous Point)

· File Location: ruoyi-generator/src/main/resources/mapper/generator/GenTableMapper.xml

Key Code:

<update id="createTable">
    ${sql}
</update>

Analysis: In MyBatis, ${} directly concatenates strings rather than using the safe precompiled #{}. This causes malicious SQL that has bypassed the filter to be sent to the database for execution. This is a typical "blacklist filtering + unsafe concatenation" combination vulnerability.

Screenshot Evidence:

04-GenTableMapper-createTable

3. PoC Logic and Exploitation Approach

3.1 Bypass Technique

· Method: The attacker uses %0b (MySQL's vertical tab, which falls within the \s matching range) to replace spaces in the SQL statement.

3.2 Complete Execution Chain Analysis

  1. HTTP passes in a Payload with %0b: CREATE table xxx as SELECT%0b111 FROM sys_job WHERE 1=0 AND%0bIF(<condition>, 1, 1/0);
  2. The Payload enters the filterKeyword method, %0b is matched by \s and cleared, and the string becomes select111 and andIF.
  3. Since the blacklist entry is "select " (with a space), "select111".indexOf("select ") returns -1, successfully bypassing the blacklist interception.
  4. The dangerous parameter enters MyBatis, and ${sql} concatenates it into the database.
  5. When MySQL parses it, %0b is treated as a valid whitespace character, and the SQL is successfully injected and executed.

3.3 Blind Injection Automation Approach

· Detection Principle: Use IF(<condition>, 1, 1/0) as the detector for boolean blind injection. · Condition is false: Triggers a division-by-zero error, and the server returns HTTP 500. · Condition is true: Normal, no error. · Extraction Method: Using binary search, database data can be guessed bit by bit.


4. Summary and Remediation Recommendations

4.1 Summary of Vulnerability Root Cause

This vulnerability is a typical bypass caused by "incomplete remediation." When the developer fixed a previous similar SQL injection, they introduced a blacklist mechanism, but overlooked that the blacklist depends on spaces, while the preceding logic that clears spaces breaks the blacklist's matching conditions, ultimately leading to a new bypass (CVE-2024-57521).

4.2 Remediation Recommendations

· Abolish the blacklist mechanism: Do not rely on blacklists; a whitelist mechanism is the foundation of security. · Use precompilation: Change ${sql} in MyBatis to the #{} precompiled approach. If SQL must be passed dynamically (such as for table creation or Order By), strict Abstract Syntax Tree (AST) parsing or strict parameter validation should be used. · Improve the filter: If a blacklist must be used, remove the trailing spaces from the blacklist keywords and perform unified normalization before comparison (e.g., uniformly convert to lowercase, replace %0b etc. with spaces).


5. Reference Links

· NVD - CVE-2024-57521 · RuoYi-Vue Gitee Repository

6. Automated PoC Script (Based on Error-Based Injection)

  • File Location: poc/poc_boolean.py (Note: It is recommended to rename the file to poc_error_based.py later to match the actual logic)
  • Implementation Principle: Uses the extractvalue() function to trigger an XPath error, and extracts data by regex-matching XPATH syntax error: '~...~'. The Payload uses /**/ instead of spaces to bypass blacklist filtering.
  • Core Payload:

CREATE//table//{random table name}//as//SELECT/**/extractvalue(1,concat(0x7e,({query statement}),0x7e))

  • Test Notes: In a locally built RuoYi test environment, the feasibility of the %0b WAF bypass and extractvalue error-based injection was successfully verified. The script has stably extracted the MySQL version (5.7.26), the current database name (ry), and the database connection user (root@localhost).
도구 다운로드