Skip to content
Threat Feed
high threat

SQL Injection Vulnerability in Purchase Order Management System (POMS)

Purchase Order Management System (POMS) version 1.0 is vulnerable to unauthenticated SQL injection via the password parameter, allowing for exfiltration or out-of-band communication via the MySQL load_file function.

Purchase Order Management System (POMS) version 1.0 is affected by a critical SQL injection vulnerability in its login authentication logic. The vulnerability exists within the 'password' parameter processed by '/purchase_order/classes/Login.php'. An attacker can send a crafted POST request to this endpoint to execute arbitrary SQL sub-queries. The proof-of-concept demonstrates the use of the MySQL 'load_file' function to perform an out-of-band (OOB) DNS lookup, which confirms that the application can be forced to interact with attacker-controlled external infrastructure. This vulnerability poses a significant risk to the integrity and confidentiality of the database connected to the application, as successful exploitation could lead to credential harvesting or database dumping.

Attack Chain

  1. The attacker identifies the login endpoint at '/purchase_order/admin/login.php'.
  2. The attacker crafts an HTTP POST request targeting '/purchase_order/classes/Login.php?f=login'.
  3. The attacker injects a malicious SQL string into the 'password' field.
  4. The payload utilizes the 'load_file' function to reference a UNC path, forcing a DNS request to an external domain.
  5. The application backend processes the request and executes the injected SQL command.
  6. The external OAST server (e.g., OASTify) receives the DNS query, confirming successful injection.
  7. The attacker proceeds to extract sensitive information or bypass authentication mechanisms.

Impact

Successful exploitation of this vulnerability allows unauthenticated attackers to interact with the underlying MySQL database. This can lead to unauthorized access to system credentials, the theft of sensitive procurement data, or potential further compromise of the web application environment.

Recommendation

  1. Implement input sanitization and parameterization for all user-supplied data in 'classes/Login.php', specifically for the 'username' and 'password' parameters.
  2. Deploy the provided Sigma rule to detect malicious SQL injection patterns in web server logs.
  3. Block outbound DNS requests from the web application server to untrusted or non-whitelisted domains to prevent OOB exfiltration.
  4. Audit logs for anomalous activity targeting the '/purchase_order/classes/Login.php' endpoint.

Immediate actions

Deploy WAF rule to inspect POST requests to /purchase_order/classes/Login.php for SQL injection keywords.

SOC 24h

Threat Hunt

Search web logs for POST requests containing 'load_file' or SQL comment characters in the request body.

T1190 high high confidence hunt now

Data: webserver_logs

Mitigations

Sanitize and parameterize all input fields on POMS login forms.

immediate IT Operations

SQL Injection vulnerability in Login.php

Detection coverage 1

Detect POMS Login SQL Injection Attempt

high

Detects potential SQL injection attempts targeting the POMS login endpoint by looking for suspicious SQL functions like load_file in POST requests.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →

Indicators of compromise

1

domain

TypeValue
domainy10in4ofvosyskgb5c9a7e55mwssgkf86bu3hu5j.oastify.com