用友某系统存在通用SQL注入

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### 简要描述: 用友某系统存在通用SQL注入 ### 详细说明: 用友FE协作办公平台最新版 漏洞url: ``` /security/role_add_user.jsp?dept=1&roleid=2&searchValue=3 ``` 部分代码 ``` <% // String searchValue=HtmlFormat.format(request.getParameter("searchValue"));//这个参数 String filter=""; Dao dao=(Dao)ResourceManage.getContext("basicDao"); FieldSet groupFs=dao.getFieldSetByFilter("SYS_GROUP","SG04='/'"); String groupName=groupFs.getString("SG03"); DataTable dataTable=null; if(!"".equals(roleId)){ if(!groupName.equals(dept)) filter=" and su00 not in (select su00 from user_role_v where sr03='"+dept+"' and sr00 = "+roleId+")" ; else filter=" su00 not in (select su00 from user_role_v where sr03='"+dept+"' and sr00 = "+roleId+")" ; } if(!"".equals(searchValue)){ filter=filter+" and (su02 like '%"+searchValue+"%' or SU01 like '%"+searchValue+"%')"; } if(!groupName.equals(dept)){ dataTable=dao.getDataTable("GROUP_USER_V"," sg03='"+dept+"'"+filter,"gu03"); } else{ dataTable=dao.getDataTable("SYS_USERS",filter,"SU03"); } %> ```...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息