Technology Sharing

Tongxiang TXEHR V15 Human Resources Management Platform DownloadFile Interface Arbitrary File Download Vulnerability Reappearance [Attached POC]

2024-07-12

한어Русский языкEnglishFrançaisIndonesianSanskrit日本語DeutschPortuguêsΕλληνικάespañolItalianoSuomalainenLatina

Tongxiang TXEHR V15 Human Resources Management Platform DownloadFile Interface Arbitrary File Download Vulnerability Reappearance [Attached POC]

0x01 Introduction

Disclaimer: Please do not use the relevant technologies in this article for illegal testing. Any direct or indirect consequences and losses caused by the dissemination and use of the information or tools provided in this article are the responsibility of the user himself, and all adverse consequences have nothing to do with the author of the article. This article is for learning purposes only! ! !

0x02 Vulnerability Description

Tongxiang Software was founded in 1997, and its operation center is located in Nancheng Nanxin Industry International, Dongguan. It focuses on the research and development and promotion of human resources information products, helping enterprises build a unified human resources digital platform, quickly improving enterprise talent management capabilities, improving human resources management efficiency, helping employees grow rapidly, and assisting enterprises in making smart decisions. Tongxiang TXEHR V15 human resources management platform DownloadFile has an arbitrary file download vulnerability.

0x03 Affected Versions

同享TXEHR V15人力管理平台
  • 1

0x04 Vulnerability Environment

FOFA Syntax:body=“/Assistant/Default.aspx”
insert image description here

0x05 Vulnerability Recurrence