PT-2025-22367 · Kingdee · Kingdee Cloud Galaxy Private Cloud Bbc System

Caichaoxiong

·

Published

2025-05-21

·

Updated

2025-05-21

·

CVE-2025-5029

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Kingdee Cloud Galaxy Private Cloud BBC System versions up to 9.0 Patch April 2025
Description A critical issue has been found, affecting the BaseServiceFactory.getFileUploadService.deleteFileAction function of the fileUpload/deleteFileAction.jhtml file in the File Handler component. The manipulation of the filePath argument leads to path traversal. This issue can be exploited remotely.
Recommendations Apply a patch to fix this issue for Kingdee Cloud Galaxy Private Cloud BBC System versions up to 9.0 Patch April 2025. As a temporary workaround, consider restricting access to the fileUpload/deleteFileAction.jhtml file or the BaseServiceFactory.getFileUploadService.deleteFileAction function to minimize the risk of exploitation. Avoid using the filePath argument in the affected component until the issue is resolved.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-5029

Affected Products

Kingdee Cloud Galaxy Private Cloud Bbc System