We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
v1.7.8
积木报表软件存在AviatorScript代码注入RCE漏洞
使用接口/jmreport/save处在text中写入AviatorScript表达式 访问/jmreport/show触发AviatorScript解析从而导致命令执行。
访问官网,创建报表,在报表表格中写入AviatorScript表达式
访问创建的报表
触发命令执行,获取官网服务器权限
The text was updated successfully, but these errors were encountered:
cr
Sorry, something went wrong.
已修复,待新版本发布。
No branches or pull requests
版本号:
v1.7.8
问题描述:
积木报表软件存在AviatorScript代码注入RCE漏洞
使用接口/jmreport/save处在text中写入AviatorScript表达式
访问/jmreport/show触发AviatorScript解析从而导致命令执行。
错误截图:
访问官网,创建报表,在报表表格中写入AviatorScript表达式
访问创建的报表
触发命令执行,获取官网服务器权限
友情提示:
The text was updated successfully, but these errors were encountered: