References https://www.cnblogs.com/pursue-security/p/17673630.html https://github.com/adysec/POC/blob/main/wpoc/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-office%E7%B3%BB%E7%BB%9FUserSelect%E6%8E%A5%E5%8F%A3%E5%AD%98%E5%9C%A8%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE%E6%BC%8F%E6%B4%9E.md https://www.saury.net/1342.html https://cn-sec.com/archives/2682375.html https://blog.csdn.net/qq_34780861/article/details/138075008 https://www.hackjie.com/docs/3330.html https://github.com/adysec/POC/blob/main/wpoc/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEe-office%20%E6%9C%AA%E6%8E%88%E6%9D%83%E8%AE%BF%E9%97%AE.md https://blog.csdn.net/qq_18193739/article/details/134020652
Related VulnerabilitiesPoCdzzoffice-installer: DzzOffice - Installer Page Exposure上海必智科技有限公司律师E通userID和officeID参数存在SQL注入漏洞泛微e-office /iWebOffice/Signature/SignatureDel.php SQL 注入漏洞用友政务财务系统 /billdesigner/office/downloadTemplate 文件读取漏洞万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞上海必智科技有限公司律E通emp_office_id参数存在SQL注入漏洞致远 OA /seeyon/officeservlet 信息泄露漏洞PoCCVE-2026-25512: Group-Office < 26.0.5 - Remote Code ExecutionPoCCVE-2025-5301: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting新视窗新一代物业管理系统 /OfficeManagement/RegisterManager/Report/Training/Report/GetprintData.asmx SQL 注入漏洞万户OA /defaultroot/modules/govoffice/gov_documentmanager/govdocumentmanager_sendfile_gd.jsp;.js SQL 注入漏洞