Security Analysis of Zhiyuan OA Unauthorized Access and File Upload Vulnerabilities
Vulnerability Reproduction Process
The vulnerability reproduction consists of three main components:
1.1 Unauthorized Access Detection
Following the analysis by unicodeSec, we can identify the vulnerability by making a request to the endpoint eyon/thirdpartyController.do.css/…;/ajax.do. If the response shows an exception as depicted below, the system likely contains the vulnerability.
By capturing network traffic, we can observe the following request and response structure:
The response status code is 200, and the returned data contains the string "java.lang.NullPointerException:null".
1.2 Arbitrary File Upload
We can utilize the unauthorized file upload interface to upload arbitrary files. For example, uploading a test.txt file to the /seeyon directory with content "test123" generates the following request:
The response status code is 500, which indicates successful file upload, returning:
{
"message":null,
"code":"0844135702",
"details":null
}
Note that the code value may vary.
Failed file uploads return:
{
"message": "Forced offline, reason: lost connection to server",
"code": "-1",
"details": null
}
1.3 Accessing Uploaded Files
By making a request to the uploaded file, we can verify if the upload was successful:
Goby EXP Development
2.1 Vulnerability Information Configuration
The query rule for Zhiyuan OA is: app=Yonyou-Seeyon-OA (you can detremine this by scanning the target and examining its asset type).
Fill in the vulnerability information as shown below:
In the advanced configuraiton, provide details such as tags, description, product, product homepage, author, source, vulnerability impact, and remediation solutions.
2.2 ScanSteps Configuration
2.2.1 Unauthorized Access Verification
Based on the vulnerability reproduction section, send a GET request to /seeyon/thirdpartyController.do.css/…;/ajax.do. Determine if the target is vulnerable by checking if the response status code is 200 and if the response contains the string "java.lang.NullPointerException:null". Configure the corresponding rules as follows:
The Accept field must be included in the headers.
2.2.2 File Upload Secondary Verification
After consulting with technical experts from the Goby team, we determined that relying solely on the unauthorized access check might generate false positives. Therefore, we need to use file upload for further verification.
Send POST data to perform arbitrary file upload, including the header Content-Type: application/x-www-form-urlencoded. Determine if the upload was successful by checking if the response contains message, code, and details fields, while excluding responses where the code is -1 (indicating upload failure).
The POST data can reference existing resources available online.
Pro tip: After configuring the test data, use the "Single IP Scan" option in the upper right corner of the custom PoC interface. Enter an IP:port combination to perform a scan on a single IP and verify if your defined test logic is correct.
2.3 ExploitSteps Configuration
Extract the POST data from the ScanSteps section of the generated seeyou_OA_ajaxAction_formulaManager_File_Upload.json file and add it to the ExploitSteps section as shown below: