PT-2025-26671 · Unknown · Zhiyuan Oa Platform
Pursue Security
·
Published
2025-06-24
·
Updated
2025-11-20
·
CVE-2025-34040
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions:
Zhiyuan OA versions 5.0
Zhiyuan OA versions 5.1 through 5.6sp1
Zhiyuan OA versions 6.0 through 6.1sp2
Zhiyuan OA version 7.0
Zhiyuan OA versions 7.0sp1 through 7.1
Zhiyuan OA version 7.1sp1
Zhiyuan OA versions 8.0 through 8.0sp2
Description:
An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the
wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of intended directories using path traversal. Successful exploitation enables remote code execution as the uploaded file can be accessed and executed through the web server.Recommendations:
Zhiyuan OA version 5.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Zhiyuan OA versions 5.1 through 5.6sp1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Zhiyuan OA versions 6.0 through 6.1sp2: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Zhiyuan OA version 7.0: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Zhiyuan OA versions 7.0sp1 through 7.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Zhiyuan OA version 7.1sp1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Zhiyuan OA versions 8.0 through 8.0sp2: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Path traversal
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Zhiyuan Oa Platform