Landray Landry Office Automation是中国Landray公司的一款深受大中型企业欢迎的智能化办公自动化(OA)与协同管理平台。 Landray Landry Office Automation存在SQL注入漏洞,该漏洞源于对uid POST参数输入清理不当,可能导致未经身份验证的攻击者查询任意Hibernate实体类,从而提取敏感数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Shenzhen Landray Software Co., Ltd. | Landry Office Automation (OA) | * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Shenzhen Landray Software Co., Ltd. | Landry Office Automation (OA) | * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet