GobyVuls/Glodon-Linkworks_GetUserByEmployeeCode_employeeCode_SQL_Injection_Vulnerability.md
Goby a75adccc5e
Create Glodon-Linkworks_GetUserByEmployeeCode_employeeCode_SQL_Injection_Vulnerability.md
add Glodon-Linkworks GetUserByEmployeeCode employeeCode SQL Injection Vulnerability
2023-07-14 11:29:33 +08:00

1.5 KiB

Glodon-Linkworks GetUserByEmployeeCode employeeCode SQL Injection Vulnerability

Vulnerability Glodon-Linkworks GetUserByEmployeeCode employeeCode SQL Injection Vulnerability
Chinese name 广联达-Linkworks 协同办公管理平台 GetUserByEmployeeCode 文件 employeeCode 参数 SQL注入漏洞
CVSS core 7.5
FOFA Query (click to view the results directly) body="Services/Identification/login.ashx" || header="Services/Identification/login.ashx" || banner="Services/Identification/login.ashx"
Number of assets affected 27341
Description Glodon-Linkworks collaborative office management platform is a management system that focuses on the entire life cycle of engineering projects and provides customers with digital software and hardware products and solutions.Glodon-Linkworks collaborative office management platform GetUserByEmployeeCode has a SQL injection vulnerability, and attackers can obtain sensitive information such as usernames and passwords.
Impact Glodon-Linkworks collaborative office management platform GetUserByEmployeeCode has a SQL injection vulnerability, and attackers can obtain sensitive information such as usernames and passwords.