T09 · Insecure Skill Coding Practices
- Location
examples/ihr/api/config.cfg:143- Finding
Ordinary authenticated users can persist JavaScript executed by the salary scheduler
- Content
View full analysis
Vulnerability Details
File Location:
examples/ihr/api/config.cfg:143-175; execution sink atexamples/ihr/api/salary.cfg:102,173-211
Vulnerability Type: Stored server-side JavaScript injection caused by missing role-based authorization
Risk Level: HighVulnerable Code
The update endpoint requires authentication but omits the RBAC and administrative-feature checks used by the adjacent zone-management endpoints:
json { "name" : "updateZone", "method" : "PUT", "property" : "private", "tokenChecker" : "USER", "request": [ {"name":"id", "type":"int", "must":true, "min":0}, {"name":"subsidy", "type":"float", "must":true, "min":0}, {"name":"salary", "type":"float", "must":true, "min":0}, {"name":"timeOff", "type":"int", "must":true, "min":-720, "max":720}, {"name":"fowSalary", "type":"float", "must":true, "min":0}, {"name":"oowSalary", "type":"float", "must":true, "min":0}, {"name":"wowSalary", "type":"float", "must":true, "min":0}, {"name":"name", "type":"string", "must":true, "min":1, "max":100}, {"name":"taxFunc", "type":"string", "must":true, "min":0, "max":500}, {"name":"cmt", "type":"string", "must":true, "min":0, "max":500} ], "process" : [ { "name" : "update_zone_info", "type" : "rdb", "db":"hr", "sqls" : [ "update zone set name='@{name}', subsidy=@{subsidy}, salary=@{salary}, timeOff=@{timeOff}, fowSalary=@{fowSalary}, oowSalary=@{oowSalary}, wowSalary=@{wowSalary}, taxFunc='@{taxFunc}', cmt='@{cmt}' where id=@{id}" ] } ] }The persisted val ...[truncated 3108 chars]
- Remediation
View remediation
Remediation Suggestions
-
Apply the same authorization controls used by the other zone administration endpoints:
json "property": "private", "tokenChecker": "USER", "aclChecker": "RBAC", "feature": "admin" -
Do not represent tax formulas as arbitrary JavaScript. Replace
taxFuncwith structured tax brackets or a constrained expression language supporting only approved arithmetic and comparisons. -
If programmable formulas are unavoidable:
- Parse the formula into an AST and allowlist permitted operators, variables, and return statements.
- Reject property access, loops, function creation, global identifiers, and runtime API references.
- Execute formulas in a capability-free sandbox with strict CPU, memory, and time limits.
- Never expose
DB,Mesh, filesystem, process, or network capabilities to the formula.
-
Validate authorization before writing the configuration, not only before displaying its administrative UI.
-
Record the authenticated account, old formula, new formula, timestamp, and zone ID in an immutable audit log.
-
Review existing
zone.taxFuncvalues for unexpected code and replace any untrusted formulas before running the salary scheduler. -
Add regression tests proving that an ordinary
USERtoken receives an authorization error fromupdateZone.
-
