References https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E4%B9%9D%E6%80%9DOA/%E4%B9%9D%E6%80%9DOA%E7%B3%BB%E7%BB%9FworkflowSync.getUserStatusByRole.dwr%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5.md https://www.secevery.com/toBugInfo?id=1859898336062783490 https://cn-sec.com/archives/2529836.html https://www.ddpoc.com/DVB-2024-6107.html https://github.com/szjr123/JiusiOAExploitTool https://ddpoc.com/DVB-2024-6843.html https://cn-sec.com/archives/3457221.html https://www.aqtd.com/nd.jsp?id=7928 https://www.ddpoc.com/DVB-2024-8506.html https://cn-sec.com/archives/3478927.html https://www.cnvd.org.cn/flaw/show/CNVD-2016-08494
Related VulnerabilitiesPoC九思OA /jsoa/workflow/dwr/exec/workflowSync.getUserStatusByRole.dwr SQL 注入漏洞九思OA /jsoa/OfficeServer 文件上传漏洞PoCjiusi-oa-userlist3g-sqli: 九思OA软件user_list_3g.jsp存在SQL注入九思OA /jsoa/services/AppService.AppServiceHttpSoap12Endpoint/ XML 外部实体注入漏洞九思OA SAVEFILE 接口存在文件上传覆盖漏洞九思OA OfficeServer存在SQL注入漏洞九思OA AppService XXE漏洞PoC九思OA /jsoa/dl.jsp 文件读取漏洞九思协同办公系统 /jsoa/workflow/dwr/exec/workflowSync.getUserStatusByRole.dwr 存在SQL注入漏洞