用友 U8 CRM 在 V16.5 之前及 V18 版本中存在任意文件读取漏洞,位于 。未经身份验证的攻击者可以利用 参数绕过认证,并通过未经验证的 参数读取任意文件。攻击者可利用此漏洞读取 Web 应用目录之外的敏感文件,包括包含数据库或服务凭据的配置文件。该漏洞的首次利用证据由 Shadowserver 基金会于 2023-10-14 发现。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet