References https://blog.csdn.net/qq_34780861/article/details/137801061 https://blog.csdn.net/qq_18193739/article/details/134020652 https://www.cnblogs.com/pursue-security/p/17677400.html https://ta0ing.github.io/article/b8b3650.html https://github.com/eeeeeeeeee-code/POC/blob/main/wpoc/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AE-eoffice-webservice-file-upload%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md https://www.cnblogs.com/pursue-security/p/17677408.html https://github.com/Nriver/wy876-POC/blob/main/%E6%B3%9B%E5%BE%AEOA/%E6%B3%9B%E5%BE%AEE-Office-uploadfile.php%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E4%B8%8A%E4%BC%A0%E6%BC%8F%E6%B4%9E.md
Related VulnerabilitiesPoCdzzoffice-installer: DzzOffice - Installer Page ExposuremotionEye /picture/ 目录遍历漏洞(CVE-2026-31978)上海必智科技有限公司律师E通userID和officeID参数存在SQL注入漏洞Interlib /interlib/loan/PictureUpload 文件上传漏洞泛微e-office /iWebOffice/Signature/SignatureDel.php SQL 注入漏洞用友政务财务系统 /billdesigner/office/downloadTemplate 文件读取漏洞万户 ezOFFICE /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../platform/bpm/work_flow/operate/wf_relation.jsp SQL 注入漏洞上海必智科技有限公司律E通emp_office_id参数存在SQL注入漏洞致远 OA /seeyon/officeservlet 信息泄露漏洞Langflow /api/v1/files/profile_pictures/../secret_key 文件读取漏洞(CVE-2026-33497)PoC友数聚科技-CPAS审计管理系统V4 /cpasm4/static/..;/mobileUploadPictureController/doDownLoadPicFile 文件读取漏洞PoCCVE-2026-25512: Group-Office < 26.0.5 - Remote Code ExecutionPoCCVE-2025-5301: ONLYOFFICE Docs (DocumentServer) - Reflected Cross-Site Scripting