PT-2026-21367 · Unknown · Megagao Ssm-Erp+1

Jszdk

·

Published

2026-02-21

·

Updated

2026-02-21

·

CVE-2026-2864

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions feng ha ha/megagao ssm-erp and production ssm (affected versions not specified)
Description A path traversal issue exists due to manipulation of the picName argument within the pictureDelete function of the PictureController.java file. This allows for remote exploitation. The exploit has been publicly disclosed. The software does not utilize versioning, making it difficult to determine specific affected and unaffected releases. The product is distributed under two different names.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2026-2864

Affected Products

Megagao Ssm-Erp
Production Ssm