Skip to content

RCE vulnerability in Cmswing v1.3.7 #56

@Jason1314Zhang

Description

@Jason1314Zhang

Find a RCE vulnerability in cmswing project version 1.3.7,Details can be found in the analysis below.

Local Test

1.Enter the background of the system, select update_channel module,then edit it.

11

2.Change log rule [user|console.log(require('child_process').execSync('ipconfig').toString('utf-8'))] or [user|console.log(require('child_process').execSync('calc').toString('utf-8'))]

7

3.Enter [System settings] - [Navigation settings], change a navigation .

3

4.Change anything, then save it. We can find that our code is executed

4

5. Get IP and open calc.

8
9

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions