Weaver e-Bridge 存在一个未认证的任意文件读取漏洞,攻击者可以通过向 saveYZJFile 端点的 downloadUrl 参数提供 file: URL,从而远程访问主机系统上的任意文件。攻击者可利用此漏洞读取敏感文件,例如 /etc/passwd、配置文件和凭证文件。此外,同一端点对 http(s) URL 的支持还允许攻击者针对内部网络资源实施服务器端请求伪造(SSRF)。该漏洞的利用证据最早由 Shadowserver Foundation 于 2023 年 10 月 17 日观察到。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet