SQL Injection Vulnerability in Purchase Order Management System (POMS)
Purchase Order Management System (POMS) version 1.0 is vulnerable to unauthenticated SQL injection via the password parameter, allowing for exfiltration or out-of-band communication via the MySQL load_file function.
Purchase Order Management System (POMS) version 1.0 is affected by a critical SQL injection vulnerability in its login authentication logic. The vulnerability exists within the 'password' parameter processed by '/purchase_order/classes/Login.php'. An attacker can send a crafted POST request to this endpoint to execute arbitrary SQL sub-queries. The proof-of-concept demonstrates the use of the MySQL 'load_file' function to perform an out-of-band (OOB) DNS lookup, which confirms that the application can be forced to interact with attacker-controlled external infrastructure. This vulnerability poses a significant risk to the integrity and confidentiality of the database connected to the application, as successful exploitation could lead to credential harvesting or database dumping.
Attack Chain
- The attacker identifies the login endpoint at '/purchase_order/admin/login.php'.
- The attacker crafts an HTTP POST request targeting '/purchase_order/classes/Login.php?f=login'.
- The attacker injects a malicious SQL string into the 'password' field.
- The payload utilizes the 'load_file' function to reference a UNC path, forcing a DNS request to an external domain.
- The application backend processes the request and executes the injected SQL command.
- The external OAST server (e.g., OASTify) receives the DNS query, confirming successful injection.
- The attacker proceeds to extract sensitive information or bypass authentication mechanisms.
Impact
Successful exploitation of this vulnerability allows unauthenticated attackers to interact with the underlying MySQL database. This can lead to unauthorized access to system credentials, the theft of sensitive procurement data, or potential further compromise of the web application environment.
Recommendation
- Implement input sanitization and parameterization for all user-supplied data in 'classes/Login.php', specifically for the 'username' and 'password' parameters.
- Deploy the provided Sigma rule to detect malicious SQL injection patterns in web server logs.
- Block outbound DNS requests from the web application server to untrusted or non-whitelisted domains to prevent OOB exfiltration.
- Audit logs for anomalous activity targeting the '/purchase_order/classes/Login.php' endpoint.
Immediate actions
Deploy WAF rule to inspect POST requests to /purchase_order/classes/Login.php for SQL injection keywords.
Threat Hunt
Search web logs for POST requests containing 'load_file' or SQL comment characters in the request body.
Data: webserver_logs
Mitigations
Sanitize and parameterize all input fields on POMS login forms.
SQL Injection vulnerability in Login.php
Detection coverage 1
Detect POMS Login SQL Injection Attempt
highDetects potential SQL injection attempts targeting the POMS login endpoint by looking for suspicious SQL functions like load_file in POST requests.
Detection queries are available on the platform. Get full rules →
Indicators of compromise
1
domain
| Type | Value |
|---|---|
| domain | y10in4ofvosyskgb5c9a7e55mwssgkf86bu3hu5j.oastify.com |