天锐绿盾审批系统 uploadWxFile.do 存在任意文件上传漏洞

2025-07-29 天锐绿盾审批系统 PoC Public

Description

天锐绿盾审批系统 uploadWxFile.do存在任意文件上传漏洞,未经身份验证的攻击者可通过该接口上传任意文件,webshell获取主机权限,可能导致企业数据泄露和安全风险。

PoC

/trwfe/file/updateCancelWMVal.do/../../config/uploadWxFile.do

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities