taogogo / taocms

taoCMS is an incredible tiny CMS( Content Management System) , writen in PHP and support MySQL/Sqlite as the database(MIT License)
MIT License
60 stars 21 forks source link

There is SQL blind injection at "Management Link" #14

Open bkfish opened 2 years ago

bkfish commented 2 years ago

analysis

The location of the vulnerability is line 33 in taocms\include\Model\Article.php, and the incoming sql statement in the update() method does not use intval to process id,and Link.php extends Article image

image

poc

edit link image image then edit id as 2)and+sleep(5)--+ image