PT-2025-3828 · Kaiyuantong · Kaiyuantong Ect Platform

Glzjin

·

Published

2025-01-09

·

Updated

2025-01-09

·

CVE-2025-0328

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions KaiYuanTong ECT Platform versions up to 2.0.0
Description A critical issue has been found in the HTTP POST Request Handler component of the affected software, specifically in the file /public/server/runCode.php. The manipulation of the code argument leads to command injection. This issue can be exploited remotely. The exploit has been disclosed publicly, and the vendor was contacted about this disclosure but did not respond.
Recommendations For KaiYuanTong ECT Platform versions up to 2.0.0, as a temporary workaround, consider disabling the runCode.php file or restricting access to the HTTP POST Request Handler component until a patch is available. Avoid using the code argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-0328

Affected Products

Kaiyuantong Ect Platform