美特CRM /getFile 文件读取漏洞

2025-11-07 美特CRM PoC No

Description

美特CRM系统的 /getFile 接口存在任意文件读取漏洞。该接口通过 p 参数接收 AES-128-ECB-PKCS5Padding 加密后的文件路径JSON(Hex格式),攻击者可通过对目标文件路径JSON加密,构造恶意请求读取服务器敏感文件。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities