References https://github.com/adysec/POC/blob/main/wpoc/%E4%BD%B3%E4%BC%9A%E8%A7%86%E9%A2%91%E4%BC%9A%E8%AE%AE/%E4%BD%B3%E4%BC%9A%E8%A7%86%E9%A2%91%E4%BC%9A%E8%AE%AEattachment%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96.md https://blog.csdn.net/weixin_45790890/article/details/142219173 https://cn-sec.com/archives/2763010.html https://cn-sec.com/archives/2761748.html
Related Vulnerabilities仁和兴业(深圳)软件有限公司仁和云ERP attachmentdownloadAttachment 接口存在任意文件读取漏洞PoCCVE-2025-14047: User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment Deletion大华智慧园区综合管理平台 /portal/itc/attachment_downloadByUrlAtt.action 文件读取漏洞安科瑞智能环保云平台uploadAttachment存在任意文件上传漏洞秒优科技-供应链管理系统 /Content/page/attachmentImg.aspx 信息泄露漏洞秒优科技-供应链管理系统 /Content/page/attachmentImg.aspx 文件读取漏洞IP-guard /ipg/console/Log/download_attachment 文件读取漏洞飞企互联 FE 业务协作平台 servlet/webchat/attachment/1 文件读取漏洞友加畅捷管理系统 /Controllers/ajax/Attachment.ashx 文件读取漏洞金和OA AskAttachment.aspx SQL注入漏洞