漏洞描述 泛微 eoffice 是一款广泛应用于企业的办公自动化系统。该漏洞存在于 /E-mobile/App/Weixin/WeiServiceApi.php 接口中,攻击者可以通过发送特制的请求绕过权限验证,进而获取到管理员的权限。
相关漏洞推荐 e-weaver-eoffice-webservice-upload-fileupload: E-Weaver EOffice webservice upload file upload POC e-office-v10-sql-inject: 泛微 eoffice v10 前台 SQL 注入 POC eoffice-v9-mobile-upload-save-fileupload: 泛微 E-Office v9.5 mobile_upload_save 任意文件上传漏洞 POC eoffice-v9-uploadify-fileupload: 泛微 E-Office v9.5 uploadify 任意文件上传漏洞 POC weaver-eoffice-file-upload: Weaver E-Office v9.5 - Arbitrary File Upload 泛微E-Office SignatureDel.php SQL注入漏洞 泛微e-office SignatureDel.php sql注入漏洞 泛微e-office /webservice/upload.php 文件上传漏洞 泛微e-office sms_page.php sql注入 泛微e-office index.php sql注入 泛微 E-Office10 /eoffice10/server/ext/qysw/index.php 信息泄露漏洞 泛微e-office前台远程代码执行漏洞 泛微e-office login_other.php SQL 注入漏洞