Dayforce Payroll 的文件下载功能存在路径遍历(Path Traversal)漏洞。未经身份验证的攻击者可以发送包含文件路径参数的 GET 请求,并将该参数设置为任意路径,包括本地绝对路径,从而可能读取服务器上的任意文件。 由于未能成功联系到供应商,该漏洞目前仅在 R2026.2.0 版本中得到确认,但其他版本也可能受影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73640 | 9.3 CRITICAL | Time-based SQL Injection in Dayforce Payroll |
| CVE-2026-73641 | 5.1 MEDIUM | Multiple Reflected XSS in Dayforce Payroll |
No comments yet