References https://www.ddpoc.com/DVB-2025-9353.html https://mrxn.net/jswz/51mis-uploaddify-uploadify-rce.html https://www.secevery.com/toBugInfo?id=1864624481761017857 https://mrxn.net/jswz/51mis-upload-rce.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%81%B5%E5%BD%93CRM/%E7%81%B5%E5%BD%93CRM%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3uploadfile%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://ddpoc.com/DVB-2025-9370.html
Related Vulnerabilities灵当 CRM /crm/WeiXinApp/yunzhijia/yunzhijiaApi.php SQL 注入漏洞western-digital-mycloud-multi-uploadify-file-upload: Western Digital MyCloud Multi Uploadify File UploadPoCeoffice-v9-uploadify-fileupload: 泛微 E-Office v9.5 uploadify 任意文件上传漏洞PoChuatiandongli-oa-downloadfortrace-fileread: 灵当CRM Playforrecord.php 任意文件读取漏洞PoClingdang-crm-playforrecord-fileread: 灵当CRM Playforrecord.php 任意文件读取漏洞PoCweaver-lazyuploadify-file-upload: OA E-Office LazyUploadify - Arbitrary File UploadPoCweaver-uploadify-file-upload: OA E-Office Uploadify - Arbitrary File Upload灵当CRM yunzhijiaApi.php 存在SQL注入漏洞(CVE-2025-8345)灵当CRM /crm/WeiXinApp/marketing/index.php 服务器端请求伪造漏洞灵当CRM /crm/wechatSession/index.php 文件上传漏洞