References https://github.com/emadshanab/goby-poc/blob/main/tongda-OA-front-end-sqli.json https://www.gzqz.gov.cn/zwgk/zdlygk/shza/202309/t20230907_82330704.html https://www.cnblogs.com/yuzly/p/13690737.html https://rivers.chaitin.cn/blog/cq949d10lnechd242ph0 https://avd.aliyun.com/detail?id=AVD-2024-0938 https://stack.chaitin.com/vuldb/detail/d713d3b3-ef58-47d3-8033-3673bd3c0c47 https://github.com/luck-ying/Library-POC/blob/master/%E9%80%9A%E8%BE%BEOA/%E9%80%9A%E8%BE%BEOA11.9%E5%89%8D%E5%8F%B0sql%E6%B3%A8%E5%85%A5.py https://stack.chaitin.com/vuldb/detail/10436b30-1ceb-499c-b520-ae978ea018b2 https://github.com/Co5mos/nuclei-tps/blob/main/http/vulnerabilities/tongda/tongda-oa-use-finger-sqli.yaml https://www.sentinelone.com/vulnerability-database/cve-2024-1252/ https://github.com/rockersiyuan/CVE/blob/main/TongDa%20Sql%20inject.md
Related VulnerabilitiesPoCCVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerPoCCVE-2026-16268: Newsletters < 4.16 - Unauthenticated SSRF via SNS Bounce HandlerPoCgeoserver-jsonarraycontains-sqli: GeoServer jsonArrayContains CQL Filter - SQL InjectionPoCCVE-2024-13985: Dahua EIMS - Unauthenticated Remote Code Execution via capture_handlePoCweaver-ecology9-doc-list-sqli: Weaver E-cology9 api/doc/out/more/list SQL InjectionIvanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)深科特LEANMES /Handler/PrintUpdcate.ashx 信息泄露漏洞中成科信票务管理平台 /LoginHandler.ashx 存在SQL注入漏洞WordPress WP Responsive Images /wp-responsive-images/image_handler.php 文件读取漏洞(CVE-2026-1557)博硕控制系统接口ComboBoxAjaxHandler存在sql注入博硕工程拌和站智能管理平台 /ComboBoxAjaxHandler.ashx SQL 注入漏洞方天云ERP /GRReport/GRHandler.ashx SQL 注入漏洞深科特 LEAN MES 系统 /Handler/AutoComplete.ashx SQL 注入漏洞