CVE-2025-34040: Zhiyuan OA Platform – Arbitrary File Upload

CVE-2025-34040: Zhiyuan OA Platform - Arbitrary File Upload-渗透云记 - 专注于网络安全与技术分享
CVE-2025-34040: Zhiyuan OA Platform – Arbitrary File Upload
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2025-34040: Zhiyuan Oa Platform – Arbitrary File Upload

漏洞描述

An arbitrary file upload vulnerability exists in the Zhiyuan OA platform 5.0, 5.1 – 5.6sp1, 6.0 – 6.1sp2, 7.0, 7.0sp1 – 7.1, 7.1sp1, and 8.0 – 8.0sp2 via the wpsAssistServlet interface. The realfileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of intended directories using path traversal. Successful exploitation enables remote code execution as the uploaded file can be accessed and executed through the web server.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享