PT-2026-21360 · Feng Ha Ha · Production Ssm+2
Jszdk
·
Publicado
2026-02-21
·
Atualizado
2026-02-21
·
CVE-2026-2863
CVSS v2.0
5.5
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
feng ha ha/megagao ssm-erp and production ssm versions prior to 4288d53bd35757b27f2d070057aefb2c07bdd097
Description
A path traversal flaw exists in the
deleteFile function within the FileServiceImpl.java file. This manipulation allows for remote exploitation. The exploit has been published. The product utilizes continuous delivery with rolling releases, making specific version details for affected or updated releases unavailable. The software is distributed under two different names. The project was notified of the issue but has not responded.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Megagao Ssm-Erp
Production Ssm
Ssm-Erp