Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

积木报表软件存在AviatorScript代码注入RCE漏洞 #2848

Closed
fallingskies22 opened this issue Aug 1, 2024 · 2 comments
Closed

积木报表软件存在AviatorScript代码注入RCE漏洞 #2848

fallingskies22 opened this issue Aug 1, 2024 · 2 comments

Comments

@fallingskies22
Copy link

版本号:

v1.7.8

问题描述:

积木报表软件存在AviatorScript代码注入RCE漏洞

使用接口/jmreport/save处在text中写入AviatorScript表达式
访问/jmreport/show触发AviatorScript解析从而导致命令执行。

错误截图:

访问官网,创建报表,在报表表格中写入AviatorScript表达式
image

访问创建的报表
image

触发命令执行,获取官网服务器权限
image

image

image

友情提示:

  • 未按格式要求发帖、描述过于简单的,会被直接删掉;
  • 描述问题请图文并茂,方便我们理解并快速定位问题;
  • 如果使用的不是master,请说明你使用的分支;
@jeecgos
Copy link
Collaborator

jeecgos commented Aug 2, 2024

cr

@hoperunChen
Copy link

已修复,待新版本发布。

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants