PT-2024-33215 · Wanxing Technology · Yitu Project Management

Zty-1995

·

Published

2024-10-15

·

Updated

2024-10-17

·

CVE-2024-48779

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wanxing Technology's Yitu project Management Software version 3.2.2
Description The issue allows a remote attacker to execute arbitrary code via the platformpluginpath parameter, which specifies that the qt plugin loads the directory. This enables the attacker to potentially gain control over the system.
Recommendations For Yitu project Management Software version 3.2.2, consider restricting access to the platformpluginpath parameter to minimize the risk of exploitation. Avoid using the platformpluginpath parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-48779

Affected Products

Yitu Project Management