关键漏洞信息 漏洞编号 GHSL-2020-132 CVE-2020-24617 漏洞类型 SQL Injection Missing CSRF protection 漏洞详情 受影响产品: Mailtrain 测试版本: 1.24.1 漏洞描述: SQL injection in accessible from 攻击场景: A specially crafted page may use a CSRF vulnerability against a logged-in Mailtrain user to perform the injection even if the attacker doesn't have credentials. 示例请求: 漏洞影响 RCE (Remote Code Execution) Arbitrary file read Denial of service (DoS) or timing-based blind read if the database user is not correctly configured 漏洞时间线 2020-07-07: 报告发送给厂商 2020-07-21: 没有回复,请求确认 2020-07-21: 厂商确认并修复SQL注入漏洞 2020-08-25: CVE-2020-24617分配 发现者 GHSL team member @JarLob (Jaroslav Lobačevski)