References https://www.ddpoc.com/DVB-2021-3095.html https://stack.chaitin.com/poc/detail/4247 https://stack.chaitin.com/poc/detail/3652 https://gryffinbit.top/2023/10/20/%E5%86%99PHP%E7%AB%99%E7%9A%84exp%E6%97%B6%E9%81%87%E5%88%B0%E7%9A%84%E9%97%AE%E9%A2%98%E6%80%BB%E7%BB%93/ https://cn-sec.com/archives/tag/%E9%B8%BF%E5%AE%87%E5%A4%9A%E7%94%A8%E6%88%B7%E5%95%86%E5%9F%8E https://github.com/Nriver/wy876-POC https://zhuanlan.zhihu.com/p/1932214870562047555 https://blog.csdn.net/qq_48985780/article/details/121636430
Related VulnerabilitiesPoCCVE-2026-9103: Langflow OSS - Superuser Token IssuancePoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDOR关于用友GRP-U8Cloud产品getUsersList及getNoteCode存在信息泄露漏洞的安全通告仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞PoCCVE-2025-14047: User Frontend <= 4.2.4 - Missing Authorization to Unauthenticated Attachment DeletionPoCCVE-2026-15826: User Profile Builder 3.16.4 - Unauthenticated Authentication BypassMicroweberCMS userfiles x存在路径穿越漏洞(CVE-2026-65694)雨诺调度客户端 UserList 存在未授权访问敏感信息泄露漏洞PoCCVE-2025-6389: Sneeit WP Social WordPress Plugin - Unauthenticated RCE via call_user_funcDatart /api/v1/users/login 默认口令漏洞PoC喰星云数字化餐饮服务系统 /chainsales/head/user/addUser 权限绕过漏洞