PT-2025-26671 · Unknown · Zhiyuan Oa Platform

Pursue Security

·

Published

2025-06-24

·

Updated

2025-11-20

·

CVE-2025-34040

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: Zhiyuan OA versions 5.0 Zhiyuan OA versions 5.1 through 5.6sp1 Zhiyuan OA versions 6.0 through 6.1sp2 Zhiyuan OA version 7.0 Zhiyuan OA versions 7.0sp1 through 7.1 Zhiyuan OA version 7.1sp1 Zhiyuan OA versions 8.0 through 8.0sp2
Description: An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of intended directories using path traversal. Successful exploitation enables remote code execution as the uploaded file can be accessed and executed through the web server.
Recommendations: Zhiyuan OA version 5.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Zhiyuan OA versions 5.1 through 5.6sp1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Zhiyuan OA versions 6.0 through 6.1sp2: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Zhiyuan OA version 7.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Zhiyuan OA versions 7.0sp1 through 7.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Zhiyuan OA version 7.1sp1: At the moment, there is no information about a newer version that contains a fix for this vulnerability. Zhiyuan OA versions 8.0 through 8.0sp2: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Path traversal

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34040

Affected Products

Zhiyuan Oa Platform