References https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/oa/%E9%80%9A%E8%BE%BEOA-v11.7-auth_mobi.php-%E5%9C%A8%E7%BA%BF%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E.md https://peiqi.wgpsec.org/wiki/oa/%E9%80%9A%E8%BE%BEOA/%E9%80%9A%E8%BE%BEOA%20v11.7%20auth_mobi.php%20%E5%9C%A8%E7%BA%BF%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E.html https://blog.csdn.net/qq_44657899/article/details/118251509 https://s1xhcl.github.io/2021/03/13/%E9%80%9A%E8%BE%BEOA-v11.7-%E5%9C%A8%E7%BA%BF%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95%E6%BC%8F%E6%B4%9E/ https://www.anquanke.com/post/id/234533 https://blog.csdn.net/yiiiing/article/details/114397925
Related Vulnerabilities通达OA v11.7 delete_cascade.php SQL 注入漏洞通达OA /general/reportshop/utils/upload.php 文件上传漏洞(CNVD-2021-21890)通达OA delete_seal.php SQL 注入漏洞(CVE-2023-4165)通达OA /pda/apps/report/getdata.php 文件上传漏洞通达OA delete_log.php SQL 注入漏洞(CVE-2023-4166)tongda-handle-sqli: 通达OA handle SQL注入tongda-v11-getdata-rce: 通达OA v11.9 getdata 任意命令执行漏洞PoCCVE-2023-4166-2: 通达OA seal_manage SQL 注入