Dromara Skyeye(截至提交版本 003549ae5615bd114ba5bb8ddf6a8e8ead97c321)在 OnlyOffice 的保存回调接口 editUploadOfficeFileById 中存在服务器端请求伪造(SSRF)和缺少身份验证的漏洞。未授权的攻击者可以通过提供任意的 URL 和 key 参数,使服务器请求内部地址并覆盖任何用户存储的文件,随后通过 queryFileToShowById 接口读取受影响文件的内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107780 | 9.8 CRITICAL | Dromara Skyeye Unauthenticated OS Command Injection via textToSpeech format Parameter |
| CVE-2026-107779 | 9.8 CRITICAL | Dromara Skyeye xxl-job-admin Missing Authentication on Job Endpoints Allows RCE |
No comments yet