导言
PART
![](https://upload.hicms.com.cn/article/2025/01/173702678195788.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173702678128254.jpg)
漏洞描述
蓝凌EIS智慧协同平台f message_receiver.aspx接口存在 SQL注入漏洞,未经身份验证的恶意攻击者利用SQL注入漏洞获取数据库中的信息(例如管理员后台密码、站点用户个人信息)之外,攻击者甚至可以在高权限下向服务器写入命令,进一步获取服务器系统权限。
![](https://upload.hicms.com.cn/article/2025/01/173702678179670.jpg)
漏洞复现
漏洞详情:
1、打开自己的服务
![](https://upload.hicms.com.cn/article/2025/01/173702678072117.jpg)
2、进行漏洞验证
![](https://upload.hicms.com.cn/article/2025/01/173702678073393.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173702678038539.jpg)
修复建议
三
1、关闭互联网访问或采用白名单方式进行访问限制;
2、升级系统至安全版本。
![](https://upload.hicms.com.cn/article/2025/01/173702678010330.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173702678059540.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173702677990409.jpg)
个人星球,欢迎加入
![](https://upload.hicms.com.cn/article/2025/01/173702677919477.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173702677966743.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173702677993358.jpg)
——The End——