漏洞描述 云网OA是一款本地化部署的OA系统,具有专家级流程引擎、智能模块、在线开发环境等功能,可快速搭建和定制企业业务。该系统云网oa setup.jsp存在系统重置,攻击者可通过该漏洞重置系统所有功能,包含Web系统管理员账户密码。
相关漏洞推荐 畅捷通-TPlus /tplus/ajaxpro/ASP_sm_setupaccount_versionupdate_selectbackupfileonserver_aspx App_Web_selectbackupfileonserver.aspx.1cbd2a00.ashx 目录遍历漏洞 POC python-setup-config: Python Setup Configuration - Exposure phpMyFAQ /api/setup/backup 信息泄露漏洞(CVE-2025-69200) Atlassian Confluence /json/setup-restore.action 文件上传漏洞(CVE-2023-22518) POC phpmyadmin-setup-deserialization: Phpmyadmin Setup Deserialization POC phpmyadmin-setup: Publicly Accessible Phpmyadmin Setup POC struts-debug-mode: Apache Struts setup in Debug-Mode POC fusionauth-admin-setup: FusionAuth Exposed Admin Setup POC connectwise-setup: ConnectWise Setup Wizard - Exposure POC cubebackup-setup-installer: CubeBackup Setup Page - Exposure POC jira-setup: Atlassian JIRA Setup - Installer POC mura-cms-setup-installer: Mura CMS Setup Page - Exposure POC openemr-setup-installer: OpenEMR Setup Installation Page - Exposure