[security] 관리자 영역 권한 검증 누락 및 CSRF 토큰 누락 수정

- adm/qa_config_update.php / adm/contentformupdate.php :
  qa_include_head/tail, co_include_head/tail 가 super 가드 없이 변경 가능해
  하위 관리자가 임의 PHP 경로를 include 시킬 수 있던 LFI 위험을
  board_form_update.php 와 동일한 패턴(super 외에는 기존 값 유지)으로 차단.

- adm/member_form_update.php / adm/member_list_update.php :
  신규 회원 생성·일괄 수정 시 부여하려는 mb_level 상한 검증이 없어
  하위 관리자가 자기보다 높은 등급을 부여할 수 있던 권한 상승을 차단.

- adm/shop_admin/categorylistupdate.php /
  adm/shop_admin/itemformupdate.php :
  is_include_path_check 호출에서 두 번째 인자(is_input=1) 누락으로
  rar/php/zip wrapper 등 경로 wrapper 차단이 동작하지 않던 부분을
  is_include_path_check($file, 1) 로 강화.

- adm/shop_admin/orderdeliveryupdate.php /
  adm/shop_admin/orderpartcancelupdate.php /
  adm/sendmail_test.php :
  상태 변경 동작에 check_admin_token() 누락으로 발생하던 CSRF 위험을
  토큰 검증 추가로 차단. sendmail_test 폼에는 hidden token 필드 추가.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
thisgun
2026-05-26 03:35:29 +00:00
co-authored by Claude Opus 4.7
parent d5619707bc
commit f4f8c57a74
9 changed files with 35 additions and 2 deletions
+11
View File
@@ -29,6 +29,17 @@ $co_id = isset($_REQUEST['co_id']) ? preg_replace('/[^a-z0-9_]/i', '', $_REQUEST
$co_subject = isset($_POST['co_subject']) ? strip_tags(clean_xss_attributes($_POST['co_subject'])) : '';
$co_include_head = isset($_POST['co_include_head']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_head'], 0, 255)) : '';
$co_include_tail = isset($_POST['co_include_tail']) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($_POST['co_include_tail'], 0, 255)) : '';
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
if ($is_admin !== 'super') {
if ($w == 'u') {
$co_include_head = isset($co_row['co_include_head']) ? $co_row['co_include_head'] : '';
$co_include_tail = isset($co_row['co_include_tail']) ? $co_row['co_include_tail'] : '';
} else {
$co_include_head = '';
$co_include_tail = '';
}
}
$co_tag_filter_use = isset($_POST['co_tag_filter_use']) ? (int) $_POST['co_tag_filter_use'] : 1;
$co_himg_del = (isset($_POST['co_himg_del']) && $_POST['co_himg_del']) ? 1 : 0;
$co_timg_del = (isset($_POST['co_timg_del']) && $_POST['co_timg_del']) ? 1 : 0;
+5
View File
@@ -127,6 +127,11 @@ $sql_common = " mb_name = '{$posts['mb_name']}',
mb_9 = '{$posts['mb_9']}',
mb_10 = '{$posts['mb_10']}' ";
// 부여하려는 mb_level 상한 검증 (자기보다 높은 권한 부여 차단)
if ($is_admin !== 'super' && (int) $posts['mb_level'] >= (int) $member['mb_level']) {
alert('자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.');
}
if ($w == '') {
$mb = get_member($mb_id);
if (isset($mb['mb_id']) && $mb['mb_id']) {
+2
View File
@@ -57,6 +57,8 @@ if ($_POST['act_button'] == "선택수정") {
$msg .= $mb['mb_id'] . ' : 회원자료가 존재하지 않습니다.\\n';
} elseif ($is_admin != 'super' && $mb['mb_level'] >= $member['mb_level']) {
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 회원은 수정할 수 없습니다.\\n';
} elseif ($is_admin != 'super' && $post_mb_level >= (int) $member['mb_level']) {
$msg .= $mb['mb_id'] . ' : 자신보다 권한이 높거나 같은 등급은 부여할 수 없습니다.\\n';
} elseif ($member['mb_id'] == $mb['mb_id']) {
$msg .= $mb['mb_id'] . ' : 로그인 중인 관리자는 수정 할 수 없습니다.\\n';
} else {
+6
View File
@@ -21,6 +21,12 @@ foreach ($check_keys as $key) {
$qa_include_head = isset($qa_include_head) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_head, 0, 255)) : '';
$qa_include_tail = isset($qa_include_tail) ? preg_replace(array("#[\\\]+$#", "#(<\?php|<\?)#i"), "", substr($qa_include_tail, 0, 255)) : '';
// 최고 관리자가 아니면 include 경로 변경 불가 (board_form_update.php 와 동일 정책)
if ($is_admin !== 'super') {
$qa_include_head = isset($qaconfig['qa_include_head']) ? $qaconfig['qa_include_head'] : '';
$qa_include_tail = isset($qaconfig['qa_include_tail']) ? $qaconfig['qa_include_tail'] : '';
}
// 관리자가 자동등록방지를 사용해야 할 경우
if ($board && ($qaconfig['qa_include_head'] !== $qa_include_head || $qaconfig['qa_include_tail'] !== $qa_include_tail) && function_exists('get_admin_captcha_by') && get_admin_captcha_by()) {
include_once G5_CAPTCHA_PATH . '/captcha.lib.php';
+5
View File
@@ -9,10 +9,14 @@ if (!$config['cf_email_use'])
include_once(G5_LIB_PATH.'/mailer.lib.php');
$token = get_token();
$g5['title'] = '메일 테스트';
include_once('./admin.head.php');
if (isset($_POST['email'])) {
check_admin_token();
$_POST['email'] = strip_tags($_POST['email']);
$email = explode(',', $_POST['email']);
@@ -61,6 +65,7 @@ if (isset($_POST['email'])) {
</p>
</div>
<form name="fsendmailtest" method="post">
<input type="hidden" name="token" value="<?php echo $token; ?>">
<fieldset id="fsendmailtest">
<legend>테스트메일 발송</legend>
<label for="email">받는 메일주소<strong class="sound_only"> 필수</strong></label>
+1 -1
View File
@@ -51,7 +51,7 @@ for ($i=0; $i<$post_ca_id_count; $i++)
alert('스킨파일명에 포함될수 없는 문자가 들어있습니다.');
}
if( ! is_include_path_check($file) ){
if( ! is_include_path_check($file, 1) ){
alert('오류 : 데이터폴더가 포함된 path 또는 잘못된 path 를 포함할수 없습니다.');
}
+1 -1
View File
@@ -380,7 +380,7 @@ foreach( $check_files as $file ){
alert('스킨파일명에 포함될수 없는 문자가 들어있습니다.');
}
if( ! is_include_path_check($file) ){
if( ! is_include_path_check($file, 1) ){
alert('오류 : 데이터폴더가 포함된 path 또는 잘못된 path 를 포함할수 없습니다.');
}
+2
View File
@@ -6,6 +6,8 @@ include_once(G5_LIB_PATH.'/mailer.lib.php');
auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
define("_ORDERMAIL_", true);
$sms_count = 0;
+2
View File
@@ -4,6 +4,8 @@ include_once('./_common.php');
auth_check_menu($auth, $sub_menu, "w");
check_admin_token();
$tax_mny = isset($_POST['mod_tax_mny']) ? preg_replace('/[^0-9]/', '', $_POST['mod_tax_mny']) : 0;
$free_mny = isset($_POST['mod_free_mny']) ? preg_replace('/[^0-9]/', '', $_POST['mod_free_mny']) : 0;