An Indian security researcher, Piyush Malik has discovered an Expression Language(EL) Injection security vulnerability in Zong, a subsidiary of Paypal
According to OWASP, EL Injection is a vulnerability that allows hackers to control data passed to the EL Interpreter. In some cases, it allows attackers to execute arbitrary code on the server.
Researcher Malik stated in his blog that Zong was running an old version of Clearspace (now known as Jive software) on a subdomain.
"Clearspace is a knowledge management tool and integrates with the Spring Framework. The EL Pattern was used in a Spring JSP Tag, which made Clearspace vulnerable to this bug," Malik explained on his blog.
He found two forms on the site that were vulnerable to this bug. He was able to perform some arithmetic operations using the vulnerable domain.
One of the vulnerable urls:
https://clearspace.zong.com/login!input.jspa?unauth = $ { custom command here }
An attacker can enter an Express Language command in the 'unauth' field, which will be executed on the server. In his demo, the researcher entered a numeric command (https://clearspace.zong.com/login!input.jspa?unauth = ${100} 3 *), which is able to be executed. Paypal has offered some generous amount for finding the vulnerability. However, the researcher did not disclose the amount.
The first EL Injection vulnerability was first reported by security researchers at Minded Security in 2011. You can find the document here: https://www.mindedsecurity.com/fileshare/ExpressionLanguageInjection.pdf

