S4E just found a medium-severity finding from stack trace error detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Network Vulnerabilities·Updated Oct 8, 2024

Landray Office Automation Remote Code Execution Scanner

Detects 'Remote Code Execution (RCE)' vulnerability in Landray Office Automation (OA).

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.4k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

Landray Office Automation (OA) is an enterprise software used by organizations to streamline and automate their internal office tasks and communication processes. It is mainly utilized by medium to large-sized companies looking for efficient software to manage documents, workflows, and collaboration. The software is designed to enhance productivity and integration across various office departments, including HR, finance, and administration. It offers features like task management, document storage, and team collaboration tools, making it appealing to enterprises seeking digitization of their traditional office processes. Landray OA is widely adopted in industries looking for tailored solutions for office automation specific to their organizational needs. The product's comprehensive suite of tools aims to deliver a one-stop solution for office administration.

A Remote Code Execution (RCE) vulnerability allows an attacker to execute arbitrary code on a remote system. It is a critical security issue, typically exploited over a network by sending crafted requests to a vulnerable component of the software. RCE vulnerabilities can lead to full system control, allowing attackers to access sensitive data, install malware, or disrupt operations. The vulnerability can be leveraged without requiring local access or authentication, making it highly dangerous if unmitigated. Often, these vulnerabilities arise due to improper input validation or unsafe handling of user input. Protecting against RCE vulnerabilities is crucial to maintain the security and integrity of information systems and networks.

The technical aspect of this vulnerability lies in the "s_bean" component's "sysFormulaSimulateByJS" functionality. Specifically, the vulnerability can be triggered by crafting a GET request to the /data/sys-common/datajson.js endpoint with malicious script parameters. This endpoint is supposed to handle certain automation functionalities, but improperly filters input, allowing the execution of arbitrary JavaScript code. The query parameter "script" is exploited, enabling attackers to deliver payloads that execute system-level commands. A successful exploitation leads to retrieving execution results through a crafted request response. The presence of status_code 200 and specific response content indicates a successful vulnerability trigger in this context.

When exploited, this RCE vulnerability can result in severe consequences, including the compromise of the entire system. Attackers might gain unauthorized access to sensitive data, change configurations, or deploy additional payloads such as ransomware or other malware. The integrity and confidentiality of the data stored and processed by Landray Office Automation could be jeopardized. Furthermore, the exploitation could disrupt business operations, leading to potential downtime and financial losses. Access to confidential organizational information could also lead to identity theft or strategic business disadvantages if competitive or proprietary data is accessed.

REFERENCES

Solution Advice

To mitigate the risks associated with this Remote Code Execution vulnerability, consider the following remediation steps:

  • Regularly update the Landray Office Automation software to its latest version to incorporate patches that address known security vulnerabilities.
  • Implement strict input validation checks within the application to sanitize and validate all inputs before processing.
  • Employ a firewall and intrusion detection/prevention systems to detect and block suspicious network traffic aimed at exploiting the vulnerability.
  • Reduce the software's exposure by restricting access to critical endpoints and only permitting trusted IPs or networks.
  • Conduct regular security audits and code reviews to identify and patch other potential vulnerabilities in the application.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.