安全研究

CVE-2023-7137 Client Details System 1.0 SQL 注入:uemail 参数的经典 boolean-based 漏洞

#漏洞分析#代码审计#Web安全
深色背景下的登录表单与 SQL 注入路径示意

Client Details System 1.0 登录端点把 uemail 参数直接拼到 SQL 查询,攻击者用经典 OR 1=1 绕过登录,再丢给 SQLmap 一键导出整个数据库。

Unlock to view this content.