Dayforce 薪酬系统存在基于时间的盲注 SQL 注入(Time-Based Blind SQL Injection)漏洞,该漏洞存在于密码恢复功能中。未认证的 attackers 可以构造一个 GET 请求,并在其中一个参数中填充任意的 SQL 查询语句。由于该参数被当作 SQL 谓词(predicate)的一部分进行解析,从而导致发生基于时间的盲注 SQL 注入攻击。 由于未能成功联系到供应商,该漏洞目前仅在 R2026.2.0 版本中确认存在,但其他版本也可能受到影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73642 | 9.2 CRITICAL | Path Traversal in Dayforce Payroll |
| CVE-2026-73641 | 5.1 MEDIUM | Multiple Reflected XSS in Dayforce Payroll |
No comments yet