References https://www.cnblogs.com/pursue-security/p/17685052.html https://github.com/xhs-d/Yongyou_GRP-U8/blob/main/README.md https://github.com/zan8in/wy876-POC/blob/main/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8%E6%97%A5%E5%BF%97%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md https://github.com/MzzdToT/HAC_Bored_Writing https://www.ddpoc.com/poc/DVB-2023-4895.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BGRP-U8%E6%97%A5%E5%BF%97%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md https://bbs.decoyit.com/thread-587-1-1.html
Related Vulnerabilities泛微ecology8 getCptInfoMap 存在SQL注入漏洞PoCCVE-2026-42878: FacturaScripts - Unauthenticated phpinfo DisclosurePoCCVE-2026-11801: WPAdverts <= 2.3.2 - Information DisclosurePoCCVE-2019-11043: PHP-FPM Path Info Buffer Underflow - Remote Code ExecutionPoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information DisclosurePoCCVE-2026-27796: Homarr < 1.54.0 - Information DisclosurePoCCVE-2026-1980: WPBookit <= 1.0.8 - Unauthenticated Customer Information DisclosurePoCCVE-2026-8386: WP Go Maps < 10.0.10 - Unauthenticated Marker Information Disclosure用友GRP-U8Cloud /jmreport/loadTableData SQL 注入漏洞用友 GRP-U8Cloud /jmreport/queryFieldBySql Freemarker 命令执行漏洞东胜物流软件 /PriceCarrier/OpSailingDateInfoGridSource.aspx SQL 注入漏洞关于用友GRP-U8Cloud产品getBudgetReleaseProjectList及U8AppProxy及fbpm-modeler存在命令执行漏洞的安全通告PoCCVE-2026-22778: vLLM 0.8.3 - 0.14.0 - Information Disclosure