漏洞描述 Microsoft Power Automate是美国微软(Microsoft)公司的一个低代码自动化平台,它允许用户创建自动化工作流程,这些工作流程可以连接和集成各种应用程序和服务。 Microsoft Power Automate存在代码注入漏洞。攻击者利用该漏洞可以远程执行代码。
相关漏洞推荐 POC sharepoint-lists-api-disclosure: Microsoft SharePoint - List API Disclosure 上海普华科技PowerPMS /UploadFle/GetFilesData SQL 注入漏洞 POC sharepoint-layouts-disclosure: Microsoft SharePoint - Layouts Disclosure POC sharepoint-masterpage-disclosure: Microsoft SharePoint - Master Page Disclosure POC sharepoint-site-metadata-disclosure: Microsoft SharePoint - Site Metadata Disclosure POC sharepoint-sitepages-disclosure: Microsoft SharePoint - Site Pages Disclosure POC CVE-2025-49706: Microsoft SharePoint Server - Authentication Bypass Progress Chef Automate /api/v0/compliance/profiles/search SQL 注入漏洞(CVE-2025-8868) POC 普华科技-PowerPMS Reg.ashx接口存在SQL注入漏洞 (CVE-2025-53770)Microsoft SharePoint Server反序列化漏洞允许远程代码执行 POC 普华科技 PowerPMS /PowerPlat/FormXml/DocFile/OfficeService.aspx 文件读取漏洞 POC 普华PowerPMS /weixin3.0/Reg.ashx SQL 注入漏洞 PowerPMS File.ashx存在SQL注入漏洞