GobyVuls/CRMEB/DaTong_sid_sqli
2021-09-16 18:00:53 +08:00
..
2021-09-16 18:00:33 +08:00

CRMEB DaTong sid sqli

CRMEB open version v4 is a free and open source mall system, UINAPP+thinkphp6 framework mall. The sid parameter under the path of CRMEB open version /api/products has unfiltered SQL statement splicing, resulting in SQL injection.

FOFA query rule: body="CRMEB" && body="/h5/js/app"

Demo

CRMEB_DaTong_sid_sqli