Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Dptcc

#41547de 53,625
6.5CVSS total
Vulnerabilidades · 1
PT-2026-3539
6.5
2026-01-20
Unknown · Bjskzy Zhiyou Erp · CVE-2026-1218
**Name of the Vulnerable Software and Affected Versions** Bjskzy Zhiyou ERP versions prior to 11.0 **Description** A flaw exists in Bjskzy Zhiyou ERP that allows for xml external entity reference manipulation. This issue is present in the `initRCForm` function within the `RichClientService.class` file of the `com.artery.richclient.RichClientService` component. The attack can be carried out remotely. The exploit is publicly available. The vendor was notified but did not respond. **Recommendations** Versions prior to 11.0 should be updated. As a temporary workaround, consider restricting access to the `RichClientService` component to minimize the risk of exploitation.