Arbitrary File Upload Vulnerability in Okcat Parking Management Platform by ZONG YU
CVE-2025-4556

9.3CRITICAL

Key Information:

Vendor

Zong Yu

Vendor
CVE Published:
12 May 2025

What is CVE-2025-4556?

The web management interface of the Okcat Parking Management Platform developed by ZONG YU is susceptible to an Arbitrary File Upload vulnerability. This flaw permits unauthenticated remote attackers to upload malicious files, specifically web shells. Once executed, these web shells allow the attackers to gain unauthorized access and execute arbitrary code on the server, posing significant security risks to the application's integrity and data safety.

Affected Version(s)

Okcat Parking Management Platform 0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-4556 : Arbitrary File Upload Vulnerability in Okcat Parking Management Platform by ZONG YU