References https://mrxn.net/jswz/yonyou-nc-oncelogin-getAuth-sqli.html https://www.ufida168.com/case_detail/4634.html https://security.yonyou.com/ https://mdr.skyeye.qianxin.com/forum/topic/48/articles?page=2 https://mrxn.net/tag/%E7%94%A8%E5%8F%8B
Related Vulnerabilities思考軟體科技|EFence - 存在3個漏洞PoCCVE-2024-1708: ConnectWise ScreenConnect <= 23.9.7 - Path TraversalPoCCVE-2026-8236: Concrete CMS <9.5.1 - Unauthenticated File-Usage Internal Metadata DisclosurePoCCVE-2026-8237: Concrete CMS <= 9.5.0 - Unauthenticated Conversation Message Disclosure (IDOR)PoCibm-websphere-ssrf: IBM WebSphere HCL Digital Experience - Server-Side Request ForgeryPoCCVE-2026-53976: OpenChamber <1.13.0 - Unauthenticated Arbitrary File ReadPoCCVE-2026-6826: Concrete CMS <9.5.1 - Unauthenticated File Usage DisclosurePoCCVE-2026-24207: NVIDIA Triton Inference Server <= 26.02 - Authentication BypassPoCNginxWebUI /adminPage/login/getAuth 命令执行漏洞Versa Concerto /portalapi/v1/roles/option 权限绕过漏洞(CVE-2025-34027)关于NC Cloud及YonBIP高级版系统的datacollectservlet接口漏洞安全通告PoCconcrete5-installer: Concrete5 - Installer Page Exposure关于NC系统BapAnaRepDefService的sql注入漏洞的安全通告