References https://ho1l0w-by.github.io/2023/09/21/Smartbi%E7%B3%BB%E5%88%97%E6%BC%8F%E6%B4%9E%E8%AF%A6%E8%A7%A3%EF%BC%9A/ https://github.com/ax1sX/SecurityList/blob/main/Java_OA/Smartbi_Audit.md https://stack.chaitin.com/techblog/detail/142 https://www.cnblogs.com/hetianlab/p/17672337.html https://x.threatbook.com/v5/article?threatInfoID=52904 https://www.secrss.com/articles/58121?app=1 https://www.secrss.com/articles/57634 https://0xf4n9x.github.io/smartbi-monitorservice-token-disclosure.html https://www.snakin.top/posts/smartbi%E6%9D%83%E9%99%90%E7%BB%95%E8%BF%87%E6%BC%8F%E6%B4%9Ev11/ https://www.h3c.com/cn/d_202309/1930997_30003_0.htm https://blog.csdn.net/YJ_12340/article/details/131943039 https://zhuanlan.zhihu.com/p/651900003 https://zhuanlan.zhihu.com/p/651907254 https://juejin.cn/post/7267090979525509176 https://stack.chaitin.com/vuldb/detail/a610bea1-cde7-4c5a-97e7-cf885280458f https://www.cnblogs.com/hetianlab/p/17672337.html
Related VulnerabilitiesPoCCVE-2026-5032: W3 Total Cache <= 2.9.3 - Unauthenticated Dynamic Security Token DisclosurePoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File UploadPoCCVE-2026-30965: Parse Server < 8.6.21 / 9.x < 9.5.2 - Session Token ExfiltrationPoCnet-vision-default-login: Net Vision UPS Monitor - Default LoginProgress WhatsUp Gold /NmConsole/Platform/PerformanceMonitorErrors/HasErrors SQL 注入漏洞(CVE-2024-6670)PoCCVE-2024-6569: Campaign Monitor for WordPress - Information DisclosurePoCCVE-2026-41492: Dgraph <= 25.3.2 - Admin Token DisclosurePoCdownload-monitor-unauth-log-export: Download Monitor < 1.9.7 - Unauthenticated Download Log ExportPublicCMS sysUserTokenList 权限绕过漏洞PoCNginx Proxy Manager /api/tokens 默认口令漏洞PoCNode-RED /auth/token 默认口令漏洞智慧芽-知识产权信息管理系统 /innoe-passport/sso/get_token_by_account 未授权访问漏洞华测监测预警系统monitorTypes参数存在SQL注入