Post

Ruiqiyun Resetpwd Login Bypass Vulnerability

Ruiqiyun Resetpwd Login Bypass Vulnerability

Ruiqiyun resetPwd login bypass vulnerability

Vulnerability Description

Ruiqi Cloud is an enterprise private cloud, aiming to help enterprises establish private cloud storage and management systems, help enterprises achieve centralized management of documents, strengthen data security, and create a collaborative office environment that is information interoperable and data-driven.

Vulnerability Impact

Ruiqiyun v3.6

Network surveying and mapping

Vulnerability reappears

Login page

img

img

Verify POC, reset password to 1111111

/dwr/role/resetPwd

img

This post is licensed under CC BY 4.0 by the author.