Description 用友U8是一款企业资源计划(ERP)软件,广泛用于企业的财务、人力资源、供应链等管理。如果使用默认或过于简单的弱口令,可能存在弱口令漏洞,这将使U8面临未经授权的访问和潜在的攻击。
References https://github.com/Nriver/wy876-POC https://www.cnblogs.com/cwkiller/p/19030876 https://mrxn.net/jswz/yonyou-u8cloud-QuerySoapServlet-sqli.html https://baizesec.github.io/bylibrary/%E6%BC%8F%E6%B4%9E%E5%BA%93/01-CMS%E6%BC%8F%E6%B4%9E/%E7%94%A8%E5%8F%8B/%E7%94%A8%E5%8F%8B%20GRP-u8%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E/ https://cn-sec.com/archives/3167360.html https://zhi.oscs1024.com/5403.html https://cloud.tencent.com/developer/article/1843616 https://www.ufida168.com/support_detail/1697.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BU8-Cloud%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3MultiRepChooseAction%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://mrxn.net/tag/%E7%94%A8%E5%8F%8B
Related Vulnerabilities用友U8 CRM changebgflag.php SQL注入漏洞用友U8 CRM getsrvtemplate.php SQL注入漏洞用友U8+渠道管理(高级版) /download-new.jsp 文件读取漏洞用友U8+渠道管理(高级版) datacollectfile.jsp 任意文件上传漏洞用友U8+渠道管理(高级版) batchsendfile.jsp 文件上传漏洞用友U8+渠道管理(高级版) download SQL注入漏洞用友U8+渠道管理(高级版) download-new 文件读取漏洞用友U8+医药行业渠道管理插件文件上传漏洞用友U8 CRM 存在SQL注入漏洞用友-U8CRM checkselectworksheet.php SQL注入漏洞用友U8 CRM checkselectworksheet.php 存在SQL注入漏洞用友U8CRM eventsetlist 存在SQL注入漏洞