深圳勤杰软件有限公司勤杰DHR数智人力资源共享平台ScanLogin.ashx loginId参数存在SQL注入

Description

勤杰DHR数智人力资源共享平台ScanLogin.ashx loginId参数存在SQL注入,攻击者可通过该漏洞获取数据库敏感信息。

PoC

GET /HandlerNoPri/ScanLogin.ashx?Action=GetCodeStatus&loginId= HTTP/1.1
Host:

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References