漏洞描述 蓝凌 EKP 系统的/third/im/kk/webparts/getGzhInfo.jsp接口存在服务器端请求伪造(SSRF)漏洞。该接口未对传入的getGzhUrl参数进行严格的输入校验和访问控制,攻击者可通过构造恶意的 URL 地址(如指向内网资源、敏感服务或外部监控域名的地址),触发服务器以自身身份发起请求。服务器会按照攻击者指定的 URL 执行访问操作,导致攻击者可绕过网络边界限制,探测内网拓扑、访问敏感接口、窃取信息,甚至利用服务器作为跳板发起对外攻击。
相关漏洞推荐 蓝凌OA erp_data.jsp存在远程命令执行漏洞 蓝凌OA sysUiExtend.do 存在任意文件上传漏洞 蓝凌OA /sys/ui/sys_ui_component/sysUiComponent.do 命令执行漏洞 POC landray-dataxml-jsp-rce: 蓝凌OA dataxml.jsp 远程命令执行漏洞 POC landray-ekp-sysFormMainDataInsystemWebservice-fileread: Landray EKP sysFormMainDataInsystemWebservice File Read POC landray-oa-datajson-rce: Landray OA Datajson RCE POC landray-oa-kmImeetingBookWebService-fileread: Landray OA kmImeetingBookWebService File Read POC landray-oa-kmImeetingResWebService-fileread: Landray OA kmImeetingResWebService File Read POC landray-oa-loginWebserviceService-fileread: Landray OA loginWebserviceService File Read POC landray-oa-sysNotifyTodoWebService-fileread: Landray OA sysNotifyTodoWebService File Read POC landray-oa-sysNotifyTodoWebServiceEkpj-fileread: Landray OA sysNotifyTodoWebServiceEkpj File Read POC landray-oa-syssearchmain-rce: Landray sysSearchMain.do RCE POC landray-oa-sysSynchroGetOrgWebService-fileread: Landray OA sysSynchroGetOrgWebService File Read