References https://mrxn.net/jswz/youjiasoft-Attachment-file-read.html https://www.gm7.org/archives/19506 https://cn-sec.com/archives/4727577.html https://www.wlaqsys.com/archives/12830 https://mrxn.net/jswz/youjiasoft-downloadfile-file-read.html https://cn-sec.com/archives/4673779.html https://www.gm7.org/archives/18690
Related Vulnerabilities仁和兴业(深圳)软件有限公司仁和云ERP attachmentdownloadAttachment 接口存在任意文件读取漏洞PoCCVE-2025-14047: User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment Deletion友加畅捷管理系统 /ReportDesign/RepFile.ashx 文件上传漏洞大华智慧园区综合管理平台 /portal/itc/attachment_downloadByUrlAtt.action 文件读取漏洞安科瑞智能环保云平台uploadAttachment存在任意文件上传漏洞秒优科技-供应链管理系统 /Content/page/attachmentImg.aspx 信息泄露漏洞秒优科技-供应链管理系统 /Content/page/attachmentImg.aspx 文件读取漏洞IP-guard /ipg/console/Log/download_attachment 文件读取漏洞PoC友加畅捷管理系统 DataHandler.ashx XXE漏洞友加畅捷管理系统 SaveRepFileData 任意文件上传漏洞友加畅捷管理系统 /fw.asmx XML 外部实体注入漏洞