CVE-2022-39983: arbitrary file upload in the Instant Developer RD3 framework

A library in Instant Developer's RD3 framework allows arbitrary file upload and remote code execution on every web app built with versions prior to 22.5 r23.

CVE
CVE-2022-39983
Product
Instant Developer RD3 Framework < 22.5 r23
CVSS
9.8
Severity
critical
Status
patched

TL;DR

The Instant Developer RD3 framework, in versions prior to 22.5 r23, contains in the full.js library an upload endpoint that does not restrict the type of file that can be uploaded. An attacker with a valid authenticated session can upload an .aspx web shell and execute arbitrary commands on the server. The flaw affects all applications built with the vulnerable versions of the framework.

Research I carried out in my work at Tinexta Cyber, published under responsible disclosure.

Context

Instant Developer is a family of low-code platforms for building multi-channel applications. Because it is a framework, a vulnerability inside it propagates to every application that inherits its runtime: not a single product, but the entire fleet of client web apps that use it.

Details

Asset Vulnerability CVSS v3.1 Severity
Instant Developer RD3 Framework < 22.5 r23 Arbitrary File Upload 9.8 Critical
  • CWE-434: Unrestricted Upload of File with Dangerous Type
  • CVSS v3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • OWASP Top 10 2021: A04 — Insecure Design

The vulnerability lives in the framework’s full.js library. Analysing the client-side code made it possible to identify the entry point responsible for the upload and to reconstruct the request needed to send an arbitrary file. This lets an attacker upload malicious files to execute arbitrary code (for example a reverse shell) and, from there, hunt for credentials, move laterally across the infrastructure or cause disruption.

The vulnerable endpoint has the form:

https://<TARGET>/<app>/<file>.aspx/?WCI=IWFiles&WCE=&SESSIONID=<SESSION_ID>

Proof of Concept

Analysing full.js reveals the code handling the upload.

Source code of full.js

Once the request was reconstructed, it was possible to upload an .aspx reverse shell with a simple curl call:

curl -kis -F "Filedata=@<MALICIOUS_FILE>.aspx" \
  -H "Cookie: ASP.NET_SessionId=<SESSION_ID>" \
  -A Chrome \
  "https://<TARGET>/<app>/<file>.aspx/?WCI=IWFiles&WCE=&SESSIONID=<SESSION_ID>"

Reverse shell upload

Interactive reverse shell on the target server

Fix and mitigations

Rebuild the application with the latest version of the framework (22.5 r23 or later).

Vendor considerations

During disclosure the vendor provided some clarifications on the exploitation conditions and on the countermeasures introduced:

  1. Exploiting the flaw requires knowing the SessionID of an authenticated session: access to a browser with an active login session is needed.
  2. If the developer has not removed authentication from their application, since version 20.5 the system does not allow uploads in unauthenticated sessions. It is up to the programmer to validate credentials and authorise access.
  3. Since version 22.0, the application’s TEMP folder contains a file that prevents execution of arbitrary files: it must not be removed and must be installed correctly in production.
  4. On upload from an authenticated session, it is up to the programmer to decide whether to accept the file by implementing the OnFileUpload event; a rejected file is immediately removed from disk.
  5. Pro Gamma provides a general-purpose development environment: it is the programmer’s responsibility to develop the application and configure the web server when it is exposed on the internet.

Timeline

Date Event
2022-07-25 Vulnerability discovered
2022-08-24 First contact with the vendor (no reply)
2022-08-29 CVE-ID requested from MITRE
2022-09-07 Second contact with the vendor (reply received)
2022-09-15 Report shared with the vendor
2023-01-23 Version 22.5 r23 released
2023-02-15 CVE-2022-39983 assigned
2023-02-20 Security advisory published

References

← all posts