JeeWMS /rest/../cgformTemplateController.do 文件读取漏洞

2025-01-17 JeeWMS PoC No

Description

JeeWMS 是一款企业应用系统。该漏洞存在于 JeeWMS 的 AuthInterceptor 类和 cgformTemplateController 接口中,攻击者可以通过构造恶意请求绕过路径检查,并利用 showPic 接口下载任意文件。此漏洞允许未经授权的攻击者读取系统中的任意文件,可能导致敏感信息泄露。

PoC

None yet. Search at https://trap.biu.life/?ref=rss

References

Related Vulnerabilities