References https://www.aqtd.com/nd.jsp?id=5364 https://www.ddpoc.com/DVB-2024-6804.html https://cn-sec.com/archives/2724440.html https://blog.csdn.net/qq_36618918/article/details/137913919 https://mrxn.net/jswz/yonyou-u8cloud-QuerySoapServlet-sqli.html https://starmap.dbappsecurity.com.cn/info/7219 https://www.mhtsec.com/309/ https://xxhglzx.ayit.edu.cn/info/1019/1269.htm https://zhi.oscs1024.com/42753.html
Related Vulnerabilities金蝶eascloud管理控制端任意文件上传关于U9 cloud存在接口XML注入漏洞的安全通告关于U9 cloud存在接口SQL注入漏洞的安全通告关于U9 cloud存在接口无授权访问漏洞的安全通告关于U8cloud所有版本CodeSyncServlet接口存在任意文件下载漏洞的安全通告关于NC Cloud及YonBIP高级版系统的公共入口接口漏洞安全通告关于用友GRP-U8Cloud产品getUsersList及getNoteCode存在信息泄露漏洞的安全通告仁和兴业(深圳)软件有限公司仁和云ERP attachmentdownloadAttachment 接口存在任意文件读取漏洞PoCCVE-2025-14047: User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment Deletion关于U9 cloud接口存在BinaryFormatter反序列化漏洞的安全通告英華達|全家寶 Cloud - Insecure Direct Object Reference用友U8Cloud MailApproveServlet存在SQL注入漏洞