Arbitrary File Upload Vulnerability in YonBIP by Yonyou
CVE-2023-51928
9.8CRITICAL
What is CVE-2023-51928?
The vulnerability in YonBIP v3_23.05 is characterized by an arbitrary file upload flaw present in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method. This security gap enables attackers to upload specially crafted files that can lead to the execution of arbitrary code, potentially compromising system integrity and exposing sensitive data. Organizations utilizing this affected product are advised to take immediate preventive measures and monitor for any unauthorized access attempts.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published