天锐绿盾审批系统 /trwfe/login.jsp/.%2e/rest/ext/mail/update/1 命令执行漏洞

2026-01-16 天锐绿盾审批系统 PoC No

Description

天锐绿盾审批系统的 /ext/mail/update/{mailId} 接口存在 Fastjson 反序列化漏洞,该接口在处理用户提交的 JSON 数据时未进行有效的安全校验,攻击者可构造恶意 JSON 数据利用 Fastjson 反序列化缺陷,在未经授权的情况下触发服务器执行任意代码。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities