gongfuxiang / shopxo

ShopXO企业级免费开源商城系统,可视化DIY拖拽装修、包含PC、H5、多端小程序(微信+支付宝+百度+头条&抖音+QQ+快手)、APP、多仓库、多商户、多门店、IM客服,进销存遵循MIT开源协议发布、基于ThinkPHP8框架研发
https://shopxo.net
MIT License
2.64k stars 799 forks source link

[CVE-2022-42031]unrestricted file upload vulnerability #69

Closed azraelxuemo closed 1 year ago

azraelxuemo commented 2 years ago

There are a lot of file upload problems in the past,and you fix some

截屏2022-09-26 10 00 18

The exclude_ext is only php,so we can upload other ext to bypass Such as phar phtml.. There I test these exts

截屏2022-09-26 10 02 47

zip this folder, and upload

截屏2022-09-26 10 03 10 截屏2022-09-26 10 03 32

And then I modify the extension name

截屏2022-09-26 10 04 30

phtml,phar also the default suffix can be parsed by php,so we should also exclude it