泛微-Ecology10 getFieldValueFun SQL注入漏洞

2026-07-29 16:38:43 泛微Ecology10 PoC No

Description

泛微Ecology10的 getFieldValueFun接口存在SQL注入漏洞。该接口对用户输入参数缺乏有效过滤,远程攻击者无需认证即可通过构造恶意SQL语句拼接至数据库查询,窃取敏感数据。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

Related Vulnerabilities