漏洞描述 金蝶云星空-管理中心 是一款基于领先的可组装低代码PaaS平台,全面服务客户研发、生产、营销、供应链、财务等领域转型。金蝶云星空-管理中心 Kingdee.BOS.ServiceFacade.ServicesStub.DevReportService.GetBusinessObjectData.common.kdsvc 接口存在反序列化漏洞,攻击者可执行任意命令获取服务器权限。
相关漏洞推荐 Kingdee Cloud-Starry-Sky Enterprise Edition 路径遍历漏洞 POC jindie-yunxingkong-dynamicformservice-rce: 金蝶云星空DynamicFormService.CloseForm.common.kdsvc远程代码执行漏洞 POC kindee-scpsupreghandler-fileupload: 金蝶云星空ScpSupRegHandler任意文件上传 POC kingdee-cloud-user-deserialization-rce: 金蝶云星空 UserService 反序列化远程代码执行 POC kingdee-commonfileserver-fileread: 金蝶云星空 CommonFileserver 任意文件读取漏洞 POC kingdee-deserialization-rce: 金蝶云星空反序列化rce POC kingdee-eas-directory-traversal: Kingdee EAS - Local File Inclusion POC kingdee-eas-directory-traversal: Kingdee EAS - Local File Inclusion POC kingdee-erp-rce: Kingdee OA Yunxingkong kdsvc - Remote Code Execution 金蝶云星空 /Kingdee.BOS.ServiceFacade.ServicesStub.InOutDataService.GetImportOutData.common.kdsvc 命令执行漏洞 金蝶云星空 BusinessDataService.BatchLoad.common.kdsvc 远程代码执行漏洞 POC 金蝶云星空 /Kingdee.BOS.ServiceFacade.ServicesStub.AppDesigner.AppDesignerService.RecordCurDevCodeInfo.common.kdsvc 命令执行漏洞 金蝶云星空 /kingdee.BOS.ServiceFacade.ServicesStub.BusinessData.BusinessDataService.BatchLoad.common.kdsvc 代码执行漏洞