References https://www.ufida168.com/case_detail/4378.html https://www.ufida168.com/News_1/p-3024-8.html https://www.ufida168.com/news/19/
Related Vulnerabilities畅捷通T+系统 AccountExtendRuleController接口处存在反序列化漏洞畅捷通信息技术股份有限公司畅捷通T+存在SQL注入漏洞畅捷通T+ DownLoadBlockFile 存在任意文件读取漏洞PoC畅捷通T+ /tplus/FormReport/FormReportOperateAction.aspx 文件读取漏洞用友 畅捷通T+ InitContext 登录绕过漏洞用友 畅捷通T+ SaveFileInfoToFile 任意文件上传漏洞用友 畅捷通T+ GetRecordAll 敏感信息泄露漏洞畅捷通T+ ME_MemberIntegral_IntegralAdjust 存在反序列化漏洞畅捷通T+ getdecallusers信息泄露漏洞PoCCNVD-2022-60632: 畅捷通T+ SetupAccount 任意文件上传PoCyonyou-chanjet-tplus-password-reset: 用友 畅捷通T+ RecoverPassword.aspx 管理员密码修改漏洞PoCyonyou-chanjet-tplus-read-file: 用友 畅捷通T+ DownloadProxy.aspx 任意文件读取漏洞畅捷通T+ AccountAssociationEditListController 反序列化命令执行漏洞