References https://cn-sec.com/archives/4455942.html https://cn-sec.com/archives/4414256.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E4%B8%87%E6%88%B7OA/%E4%B8%87%E6%88%B7OA%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3GeneralWeb%E5%AD%98%E5%9C%A8XXE%E6%BC%8F%E6%B4%9E.md https://blog.csdn.net/qq_33608000/article/details/136642212 https://idocdown.com/app/articles/blogs/detail/16892 https://cn-sec.com/archives/3256936.html
Related Vulnerabilities万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞PoCCVE-2025-11368: LearnPress < 4.3.0 - Arbitrary Callback Execution to Information ExposurePoCo2oa /x_program_center/jaxrs/mpweixin/check XML 外部实体注入漏洞PoC万户OA /defaultroot/evo/weixin/WeiXin!callback.action XML 外部实体注入漏洞天锐绿盾审批系统 /ws/taskCommon/endCallback 代码执行漏洞天锐绿盾审批系统 endCallback fastjson 反序列化漏洞万户OA officeserver 任意文件上传漏洞红帆OA WebServiceForWeixin.asmx 存在敏感信息泄露灵当 CRM /crm/WeiXinApp/yunzhijia/yunzhijiaApi.php SQL 注入漏洞PoC万户ezOFFICE协同管理平台 /defaultroot/modules/govoffice/gov_documentmanager/receivefile_gd.jsp;.js SQL 注入漏洞