万能门店小程序 /api/wxapps/doPageGetFormList SQL 注入漏洞

2024-11-29 万能门店小程序 PoC No

Description

万能门店小程序是基于ThinkPHP5框架开发的独立应用,适用于各行各业的小程序和企业门店小程序。该漏洞存在于doPageGetFormList接口中,攻击者可以通过构造恶意的SQL语句,进行数据库的任意查询,可能导致敏感信息泄露。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities