messense / aliyundrive-webdav

阿里云盘 WebDAV 服务
MIT License
9.57k stars 1.09k forks source link

OpenWrt plugin has a command injection vulnerability #972

Closed lakemoon602 closed 4 months ago

lakemoon602 commented 4 months ago

问题描述

vuln file: https://github.com/messense/aliyundrive-webdav/openwrt/luci-app-aliyundrive-webdav/luasrc/controller/aliyundrive-webdav.lua

重现步骤

When deal with action_query_qrcode request,sid parameter is vulnerable to OS command injection. 1 2 3

版本

2.3.3

运行平台

Openwrt

日志

1

messense commented 4 months ago

都登录进路由器后台了,早有 root 权限了,纠结这点问题意义不大吧。