【漏洞修复、安全补丁】标准版被篡改首页内容问题修复

第一步,在public下搜索全部的.php文件,选择包含子目录,将除过蓝色框之外的所有.php后缀文件全部删除

第二步,修改文件crmeb/crmeb/services/upload/storage/Local.php

复制代码
if (in_array($fileHandle->getOriginalMime(), ['image/x-icon', 'image/png', 'image/gif', 'image/jpeg', 'image/jpg'])) {
    $stream = fopen($fileHandle->getPathname(), 'r');
    $content = (fread($stream, filesize($fileHandle->getPathname())));
    if (is_resource($stream)) {
        fclose($stream);
    }
    $image = @imagecreatefromstring($content);
    if ($image === false) {
        return $this->setError('文件内容不合法');
    }
}

Copy

第三步,修改文件crmeb/app/api/controller/v1/PublicController.php

复制代码
use app\services\system\config\SystemStorageServices;

Copy

复制代码
/** @var SystemStorageServices $systemStorageServices */
$systemStorageServices = app()->make(SystemStorageServices::class);
$domainArr = $systemStorageServices->getColumn([], 'domain');
$domainArr = array_merge($domainArr, [$request->host()]);
$domainArr = array_unique(array_diff($domainArr, ['']));
if (count($domainArr)) {
    $domainArr = array_map(function ($item) {
        return str_replace(['https://', 'http://'], '', $item);
    }, $domainArr);
}
$imageUrlHost = $imageUrl ? (parse_url($imageUrl)['host'] ?? $imageUrl) : $imageUrl;
$codeUrlHost = $codeUrl ? (parse_url($codeUrl)['host'] ?? $codeUrl) : $codeUrl;
if ($domainArr && (($imageUrl && !in_array($imageUrlHost, $domainArr)) || ($codeUrl && !in_array($codeUrlHost, $domainArr)))) {
    return app('json')->success(['code' => false, 'image' => false]);
}

Copy

第四步,替换文件crmeb/app/common.php中的公共方法image_to_base64和put_image

复制代码
function put_image($url, $filename = '')
    {

        if ($url == '') {
            return false;
        }
        try {
            if ($filename == '') {
                $ext = pathinfo($url, PATHINFO_EXTENSION);
                if (!in_array($ext, ['jpg', 'jpeg', 'png'])) {
                    return false;
                }
                $filename = time() . "." . $ext;
            }

            // 保存文件到指定目录
            $imgData = file_get_contents($url);
            $pattern = '/<\?php(.*?)\?>/s';
            $imgData = preg_replace($pattern, '', $imgData);
            if ($imgData !== false) {
                $path = 'uploads/qrcode/' . $filename;
                if (file_put_contents($path, $imgData) !== false) {
                    return $path;
                }
            }
        } catch (\Exception $e) {
        }

        return false;
    }

Copy

复制代码
function image_to_base64($avatar = '', $timeout = 9)
    {
        $avatar = str_replace('https', 'http', $avatar);
        try {
            $url = parse_url($avatar);
            if ($url['scheme'] . '://' . $url['host'] == sys_config('site_url')) {
                $pattern = '/<\?php(.*?)\?>/s';
                $imgData = preg_replace($pattern, '', file_get_contents(public_path() . substr($url['path'], 1)));
                return "data:image/jpeg;base64," . base64_encode($imgData);
            }
            $url = $url['host'];
            $header = [
                'User-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:45.0) Gecko/20100101 Firefox/45.0',
                'Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3',
                'Accept-Encoding: gzip, deflate, br',
                'accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.9',
                'Host:' . $url
            ];
            $dir = pathinfo($url);
            $host = $dir['dirname'];
            $refer = $host . '/';
            $curl = curl_init();
            curl_setopt($curl, CURLOPT_REFERER, $refer);
            curl_setopt($curl, CURLOPT_URL, $avatar);
            curl_setopt($curl, CURLOPT_RETURNTRANSFER, true);
            curl_setopt($curl, CURLOPT_FOLLOWLOCATION, true);
            curl_setopt($curl, CURLOPT_ENCODING, 'gzip');
            curl_setopt($curl, CURLOPT_CONNECTTIMEOUT, $timeout);
            curl_setopt($curl, CURLOPT_HTTPHEADER, $header);
            curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, FALSE);
            $data = curl_exec($curl);
            $code = curl_getinfo($curl, CURLINFO_HTTP_CODE);
            curl_close($curl);
            if ($code == 200) {
                return "data:image/jpeg;base64," . base64_encode($data);
            } else {
                return false;
            }
        } catch (\Exception $e) {
            return false;
        }
    }

Copy

第五步,重新打包h5代码,上传覆盖

相关推荐
千里马学框架1 分钟前
安卓15开机启动Fallbackhome去除--成果展示
android·性能优化·手机·车载·aosp·fallbackhome
武子康4 分钟前
大数据-10-HDFS集群 Java实现MapReduce WordCount计算 Hadoop序列化 编写Mapper和Reducer和Driver 附带PO
大数据·后端
Wgllss6 分钟前
大型异步下载器:基于kotlin+Compose+协程+Flow+Channel实现多文件异步同时分片断点续传下载
android·架构·android jetpack
vivo互联网技术6 分钟前
vivo Pulsar 万亿级消息处理实践(2)-从0到1建设 Pulsar 指标监控链路
大数据·kafka·消息队列·pulsar
Sun_light13 分钟前
AI代替大脑:用Trae助手开发颜色记忆小游戏全流程实录
前端·人工智能·html
Lucien要变强16 分钟前
Cursor! 让我们意念合一!
人工智能·ai编程·cursor
kymjs张涛22 分钟前
前沿技术周刊 2025-06-03
android·前端·ios
_一条咸鱼_24 分钟前
Android Runtime JIT编译器核心技术原理分析(36)
android·面试·android jetpack
程序员岳焱25 分钟前
深入解析Spring AI:Java生态中的AI集成利器
java·人工智能·openai
TGC达成共识27 分钟前
菌菇食用攻略:从营养解析到安全指南,解锁科学食菌
大数据·人工智能·其他·安全·百度·生活·新浪微博