漏洞描述 Oracle Business Intelligence Mobile App Designer中存在信息泄露漏洞。该漏洞是由于应用对某些输入参数验证不足导致的。攻击者可利用此漏洞访问系统中的文件。
相关漏洞推荐 POC CVE-2016-15043: WP Mobile Detector <= 3.5 - Unrestricted File Upload POC CVE-2024-35694: Wordpress WPMobile.App >= 11.42 - Cross-Site Scripting POC oracle-ebs-sqllog-exposure: Oracle EBS SQL Log - Exposure 东胜物流软件 /Areas/Mobile/Views/WMS/ZWCCX.aspx SQL 注入漏洞 POC CVE-2021-2135: Oracle WebLogic Server - Remote Code Execution POC CVE-2017-5983: JIRA Workflow Designer Plugin in Atlassian JIRA Server > 6.3.0 - Remote Code Execution (XXE) POC CVE-2023-5815: News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion Oracle Identity Manager /iam/governance/applicationmanagement/api/v1/applications/groovyscriptstatus;.wadl 命令执行漏洞(CVE-2025-61757) Oracle Identity Manager 访问控制不当漏洞 同享人力资源管理系统 /MobileService/PeiXun.asmx SQL 注入漏洞 POC CVE-2025-61757: Oracle Identity Manager REST WebServices - Authentication Bypass WordPress WooCommerce Designer Pro 插件 /wp-admin/admin-ajax.php wcdp_save_canvas_design_ajax 文件上传漏洞(CVE-2025-6440) 东胜物流软件 /Mobile/Login/UnBind SQL 注入漏洞