References https://www.cnvd.org.cn/flaw/show/CNVD-2024-37222 https://help.fanruan.com/finereport/edition-view-62775-87.html https://help.fanruan.com/finereport/edition-view-64033-0.html https://help.fanruan.com/finereport-tw/doc-view-5083.html https://help.fanruan.com/finereport/doc-view-4833.html https://cn-sec.com/archives/2217499.html https://zone.ci/aliyun/ali_nonvd/379216.html https://www.sxxdckj.com/cms/a/fan-ruan-ruan-jian-you-xian-gong-si-shu-ju-jue-ce-xi-tong-cun-zai-ruo-kou-ling-lou-dong.html https://avd.aliyun.com/detail?id=AVD-2024-1747915
Related Vulnerabilities帆软报表存在未授权访问漏洞PoCCNVD-2018-04757: 帆软报表 V8 get_geo_json 任意文件读取漏洞PoCfanruan-finereport-fr-log-rce: 帆软 FineReport Fr Log RcePoCfanruan-oa-v9-designsavevg-upload-file: 帆软报表 V9 design_save_svg 任意文件覆盖文件上传PoCseeyon-fanruan-report-server-directory-travesal: 致远OA 帆软组件 ReportServer 目录遍历漏洞PoCfine-report-v9-file-upload: FineReport v9 Arbitrary File OverwritePoCfinereport-path-traversal: FineReport 8.0 - Local File InclusionPoCfinereport-sqli-rce: FineReport SQLi - Remote Code Execution致远OA-帆软报表组件 dbcommit 命令执行漏洞帆软报表 dbcommit 命令执行漏洞帆软pdf接口远程命令执行帆软报表 /report/v9/print/ie/pdf SQL注入漏洞PoC帆软 WebReport plugin_logdb JDBC 漏洞