Panwei Oa E Cology Users Data Sensitive Information Leakage
Panwei Oa E Cology Users Data Sensitive Information Leakage
Panwei OA E-Cology users.data Sensitive information leakage
Vulnerability Description
Panwei OA E-Cology users.data allows any user to download and obtain sensitive information in OA.
Vulnerability Impact
Panwei OA E-Cology
Network surveying and mapping
Vulnerability reappears
Login page
Verify POC
1
/messager/users.data
Base64 GBK decoding can obtain sensitive data in OA
This post is licensed under CC BY 4.0 by the author.