漏洞描述 云网OA是一款本地化部署的OA系统,具有专家级流程引擎、智能模块、在线开发环境等功能,可快速搭建和定制企业业务。该系统云网oa setup.jsp存在系统重置,攻击者可通过该漏洞重置系统所有功能,包含Web系统管理员账户密码。
相关漏洞推荐 Atlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518) POC phpmyadmin-setup-deserialization: Phpmyadmin Setup Deserialization POC phpmyadmin-setup: Publicly Accessible Phpmyadmin Setup POC struts-debug-mode: Apache Struts setup in Debug-Mode POC fusionauth-admin-setup: FusionAuth Exposed Admin Setup POC connectwise-setup: ConnectWise Setup Wizard - Exposure POC cubebackup-setup-installer: CubeBackup Setup Page - Exposure POC jira-setup: Atlassian JIRA Setup - Installer POC mura-cms-setup-installer: Mura CMS Setup Page - Exposure POC openemr-setup-installer: OpenEMR Setup Installation Page - Exposure POC openfire-setup: Openfire Setup - Exposure POC setup-github-enterprise: Setup GitHub Enterprise - Detect POC zenphoto-setup: Zenphoto <1.5 Installer - Detect