References https://www.twcert.org.tw/tw/cp-132-8057-1b3fa-1.html https://www.twcert.org.tw/en/cp-139-8058-cc391-2.html https://www.cve.org/CVERecord?id=CVE-2024-8454 https://security.glexia.com/cves/CVE-2024-8454 https://www.ithome.com.tw/news/165321 https://www.twcert.org.tw/tw/lp-132-1-11-20.html https://lis.mcut.edu.tw/p/406-1013-68935,r11.php?Lang=zh-tw https://cc.nchu.edu.tw/p/404-1000-1410.php?Lang=zh-tw
Related Vulnerabilities畅捷通 T+ POSSyncService.asmx 接口SQL注入漏洞PoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File UploadServiceNow-AI-Platform /assessment_thanks.do 代码执行漏洞(CVE-2026-6875)PoCCVE-2026-6875: ServiceNow AI Platform - Pre-Auth JavaScript Sandbox Escape RCE金蝶EAS /ormrpc/services/BSHService 代码执行漏洞用友U8Cloud /ServiceDispatcherServlet 文件上传漏洞用友 U8cloud /service/XChangeServlet SQL 注入漏洞关于NC系统BapAnaRepDefService的sql注入漏洞的安全通告时空智友ERP系统 /formservice updater.uploadStudioFile 文件上传漏洞广联达OA /Mail/Services/EmailAccountOrgUserService.asmx/GetUserEmailByOrgEmails XML 外部实体注入漏洞Nezha /api/v1/server/1/service 信息泄露漏洞(CVE-2026-49397)广联达OA /Org/service/Service.asmx/GetChangeUsers 信息泄露漏洞广联达OA /GTP/IM/Services/Group/Broadcast/MsgBroadcastContent.aspx SQL 注入漏洞