[security] 관리자 영역 권한 검증 누락 및 CSRF 토큰 누락 수정
- adm/qa_config_update.php / adm/contentformupdate.php : qa_include_head/tail, co_include_head/tail 가 super 가드 없이 변경 가능해 하위 관리자가 임의 PHP 경로를 include 시킬 수 있던 LFI 위험을 board_form_update.php 와 동일한 패턴(super 외에는 기존 값 유지)으로 차단. - adm/member_form_update.php / adm/member_list_update.php : 신규 회원 생성·일괄 수정 시 부여하려는 mb_level 상한 검증이 없어 하위 관리자가 자기보다 높은 등급을 부여할 수 있던 권한 상승을 차단. - adm/shop_admin/categorylistupdate.php / adm/shop_admin/itemformupdate.php : is_include_path_check 호출에서 두 번째 인자(is_input=1) 누락으로 rar/php/zip wrapper 등 경로 wrapper 차단이 동작하지 않던 부분을 is_include_path_check($file, 1) 로 강화. - adm/shop_admin/orderdeliveryupdate.php / adm/shop_admin/orderpartcancelupdate.php / adm/sendmail_test.php : 상태 변경 동작에 check_admin_token() 누락으로 발생하던 CSRF 위험을 토큰 검증 추가로 차단. sendmail_test 폼에는 hidden token 필드 추가. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.7
parent
d5619707bc
commit
f4f8c57a74
@@ -29,6 +29,17 @@ $co_id = isset($_REQUEST['co_id']) ? preg_replace('/[^a-z0-9_]/i', '', $_REQUEST
|
||||
$co_subject = isset($_POST['co_subject']) ? strip_tags(clean_xss_attributes($_POST['co_subject'])) : '';
|
||||
$co_include_head = isset($_POST['co_include_head']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_head'], 0, 255)) : '';
|
||||
$co_include_tail = isset($_POST['co_include_tail']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_tail'], 0, 255)) : '';
|
||||
|
||||
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
|
||||
if ($is_admin !== 'super') {
|
||||
if ($w == 'u') {
|
||||
$co_include_head = isset($co_row['co_include_head']) ? $co_row['co_include_head'] : '';
|
||||
$co_include_tail = isset($co_row['co_include_tail']) ? $co_row['co_include_tail'] : '';
|
||||
} else {
|
||||
$co_include_head = '';
|
||||
$co_include_tail = '';
|
||||
}
|
||||
}
|
||||
$co_tag_filter_use = isset($_POST['co_tag_filter_use']) ? (int) $_POST['co_tag_filter_use'] : 1;
|
||||
$co_himg_del = (isset($_POST['co_himg_del']) && $_POST['co_himg_del']) ? 1 : 0;
|
||||
$co_timg_del = (isset($_POST['co_timg_del']) && $_POST['co_timg_del']) ? 1 : 0;
|
||||
|
||||
@@ -127,6 +127,11 @@ $sql_common = " mb_name = '{$posts['mb_name']}',
|
||||
mb_9 = '{$posts['mb_9']}',
|
||||
mb_10 = '{$posts['mb_10']}' ";
|
||||
|
||||
// 부여하려는 mb_level 상한 검증 (자기보다 높은 권한 부여 차단)
|
||||
if ($is_admin !== 'super' && (int) $posts['mb_level'] >= (int) $member['mb_level']) {
|
||||
alert('자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.');
|
||||
}
|
||||
|
||||
if ($w == '') {
|
||||
$mb = get_member($mb_id);
|
||||
if (isset($mb['mb_id']) && $mb['mb_id']) {
|
||||
|
||||
@@ -57,6 +57,8 @@ if ($_POST['act_button'] == "선택수정") {
|
||||
$msg .= $mb['mb_id'] . ' : 회원자료가 존재하지 않습니다.\\n';
|
||||
} elseif ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level']) {
|
||||
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 회원은 수정할 수 없습니다.\\n';
|
||||
} elseif ($is_admin != 'super' && $post_mb_level >= (int) $member['mb_level']) {
|
||||
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.\\n';
|
||||
} elseif ($member['mb_id'] == $mb['mb_id']) {
|
||||
$msg .= $mb['mb_id'] . ' : 로그인 중인 관리자는 수정 할 수 없습니다.\\n';
|
||||
} else {
|
||||
|
||||
@@ -21,6 +21,12 @@ foreach ($check_keys as $key) {
|
||||
$qa_include_head = isset($qa_include_head) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_head, 0, 255)) : '';
|
||||
$qa_include_tail = isset($qa_include_tail) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_tail, 0, 255)) : '';
|
||||
|
||||
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
|
||||
if ($is_admin !== 'super') {
|
||||
$qa_include_head = isset($qaconfig['qa_include_head']) ? $qaconfig['qa_include_head'] : '';
|
||||
$qa_include_tail = isset($qaconfig['qa_include_tail']) ? $qaconfig['qa_include_tail'] : '';
|
||||
}
|
||||
|
||||
// 관리자가 자동등록방지를 사용해야 할 경우
|
||||
if ($board && ($qaconfig['qa_include_head'] !== $qa_include_head || $qaconfig['qa_include_tail'] !== $qa_include_tail) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
|
||||
include_once G5_CAPTCHA_PATH . '/captcha.lib.php';
|
||||
|
||||
@@ -9,10 +9,14 @@ if (!$config['cf_email_use'])
|
||||
|
||||
include_once(G5_LIB_PATH.'/mailer.lib.php');
|
||||
|
||||
$token = get_token();
|
||||
|
||||
$g5['title'] = '메일 테스트';
|
||||
include_once('./admin.head.php');
|
||||
|
||||
if (isset($_POST['email'])) {
|
||||
check_admin_token();
|
||||
|
||||
$_POST['email'] = strip_tags($_POST['email']);
|
||||
$email = explode(',', $_POST['email']);
|
||||
|
||||
@@ -61,6 +65,7 @@ if (isset($_POST['email'])) {
|
||||
</p>
|
||||
</div>
|
||||
<form name="fsendmailtest" method="post">
|
||||
<input type="hidden" name="token" value="<?php echo $token; ?>">
|
||||
<fieldset id="fsendmailtest">
|
||||
<legend>테스트메일 발송</legend>
|
||||
<label for="email">받는 메일주소<strong class="sound_only"> 필수</strong></label>
|
||||
|
||||
@@ -51,7 +51,7 @@ for ($i=0; $i<$post_ca_id_count; $i++)
|
||||
alert('스킨파일명에 포함될수 없는 문자가 들어있습니다.');
|
||||
}
|
||||
|
||||
if( ! is_include_path_check($file) ){
|
||||
if( ! is_include_path_check($file, 1) ){
|
||||
alert('오류 : 데이터폴더가 포함된 path 또는 잘못된 path 를 포함할수 없습니다.');
|
||||
}
|
||||
|
||||
|
||||
@@ -380,7 +380,7 @@ foreach( $check_files as $file ){
|
||||
alert('스킨파일명에 포함될수 없는 문자가 들어있습니다.');
|
||||
}
|
||||
|
||||
if( ! is_include_path_check($file) ){
|
||||
if( ! is_include_path_check($file, 1) ){
|
||||
alert('오류 : 데이터폴더가 포함된 path 또는 잘못된 path 를 포함할수 없습니다.');
|
||||
}
|
||||
|
||||
|
||||
@@ -6,6 +6,8 @@ include_once(G5_LIB_PATH.'/mailer.lib.php');
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
check_admin_token();
|
||||
|
||||
define("_ORDERMAIL_", true);
|
||||
|
||||
$sms_count = 0;
|
||||
|
||||
@@ -4,6 +4,8 @@ include_once('./_common.php');
|
||||
|
||||
auth_check_menu($auth, $sub_menu, "w");
|
||||
|
||||
check_admin_token();
|
||||
|
||||
$tax_mny = isset($_POST['mod_tax_mny']) ? preg_replace('/[^0-9]/', '', $_POST['mod_tax_mny']) : 0;
|
||||
$free_mny = isset($_POST['mod_free_mny']) ? preg_replace('/[^0-9]/', '', $_POST['mod_free_mny']) : 0;
|
||||
|
||||
|
||||
Reference in New Issue
Block a user