References https://github.com/Sec-Fork/POC-20250106/blob/main/%E4%B9%9D%E6%80%9DOA/%E4%B9%9D%E6%80%9DOA%E7%B3%BB%E7%BB%9FworkflowSync.getUserStatusByRole.dwr%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md https://cn-sec.com/archives/2529836.html https://cn-sec.com/archives/3478927.html https://www.ddpoc.com/DVB-2024-6107.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E4%B9%9D%E6%80%9DOA/%E4%B9%9D%E6%80%9DOA%E7%B3%BB%E7%BB%9FworkflowSync.getUserStatusByRole.dwr%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md https://zhuanlan.zhihu.com/p/1932214870562047555 https://www.secevery.com/toBugInfo?id=1861030800516759554 https://blog.csdn.net/weixin_43567873/article/details/136503440 https://github.com/szjr123/JiusiOAExploitTool
Related Vulnerabilities万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞PoC九思OA /jsoa/workflow/dwr/exec/workflowSync.getUserStatusByRole.dwr SQL 注入漏洞万户OA officeserver 任意文件上传漏洞九思OA /jsoa/OfficeServer 文件上传漏洞万户ezOFFICE协同平台 /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../modules/hrm/report/customize/checkSQL_httprequest.jsp SQL 注入漏洞e-office-v10-officeserver-upload: 泛微OA E-Office OfficeServer.php 任意文件上传漏洞PoCe-cology-e-office-officeserver-file-read: 泛微OA E-Office officeserver.php 任意文件读取漏洞PoCjiusi-oa-userlist3g-sqli: 九思OA软件user_list_3g.jsp存在SQL注入PoCwanhu-oa-officeserver-upload-file: 万户OA OfficeServer.jsp 任意文件上传漏洞PoCwanhu-oa-officeserverservlet-upload-file: 万户 OA 前台无条件 GETSHELL