URP教务系统reportAction.do-文件越权访问

2021-01-19 URP教务系统 PoC No

Description

【漏洞对象】URP综合教务系统 【漏洞描述】 URP教务系统reportAction.do文件越权访问,可以使黑客直接访问到后台页面对用户进行操作。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities