导言
PART
![](https://upload.hicms.com.cn/article/2025/01/173728601248855.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173728601288725.jpg)
漏洞描述
蓝凌EIS智慧协同平台f message_receiver.aspx接口存在 SQL注入漏洞,未经身份验证的恶意攻击者利用SQL注入漏洞获取数据库中的信息(例如管理员后台密码、站点用户个人信息)之外,攻击者甚至可以在高权限下向服务器写入命令,进一步获取服务器系统权限。
![](https://upload.hicms.com.cn/article/2025/01/173728601290564.jpg)
漏洞复现
漏洞详情:
1、打开自己的服务
![](https://upload.hicms.com.cn/article/2025/01/173728601243058.jpg)
2、进行漏洞验证
![](https://upload.hicms.com.cn/article/2025/01/173728601236725.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173728601212740.jpg)
修复建议
三
1、关闭互联网访问或采用白名单方式进行访问限制;
2、升级系统至安全版本。
![](https://upload.hicms.com.cn/article/2025/01/173728601249533.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173728601256492.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173728601220851.jpg)
个人星球,欢迎加入
![](https://upload.hicms.com.cn/article/2025/01/173728601146401.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173728601139033.jpg)
![](https://upload.hicms.com.cn/article/2025/01/173728601196836.jpg)
——The End——