[建议描述]
Sourcecodester Event Registration App v1.0 被发现通过 First Name、Contact 和 Remarks 字段存在多个 CSV 注入漏洞。这些漏洞允许攻击者通过精心制作的 Excel 文件执行任意代码。
[附加信息]
Proof of Concept: https://drive.google.com/file/d/17rSb8GLFPQfqnVFI56AYffbVMDg8z75t/view?usp=sharing
Vendor Homepage: https://www.sourcecodester.com/javascript/15214/event-registration-app-export-csv-javascript-free-source-code.html
Software Link: https://www.sourcecodester.com/sites/default/files/download/oretnom23/registration.zip
[漏洞类型]
CSV 注入
[产品厂商]
Sourcecodester
[受影响产品代码库]
Event Registration App with Export to CSV in JavaScript - 1.0
[受影响组件]
源代码
[攻击类型]
远程
[影响代码执行]
是
[攻击向量]
为了利用此漏洞,攻击者需要在 First Name、Contact 和 Remarks 字段中插入一个 Excel 公式,然后点击 Save,接着点击 Export to CSV,再点击 Downloaded CSV in Excel。一旦攻击者在 Excel 中打开下载的 CSV 文件,载荷就会执行。
[参考]
https://drive.google.com/file/d/17rSb8GLFPQfqnVFI56AYffbVMDg8z75t/view?usp=sharing
https://www.sourcecodester.com/javascript/15214/event-registration-app-export-csv-javascript-free-source-code.html
https://www.sourcecodester.com/sites/default/files/download/oretnom23/registration.zip
[发现者]
RashidKhan Pathan