VDB

CVE-2025-34040

CVE-2025-34040 PUBLISHED KEV CVSS 10 CRITICAL

An arbitrary file upload vulnerability exists in the Zhiyuan OA platform 5.0, 5.1 - 5.6sp1, 6.0 - 6.1sp2, 7.0, 7.0sp1 - 7.1, 7.1sp1, and 8.0 - 8.0sp2 via the wpsAssistServlet interface. The realFileType and fileId parameters are improperly validated during multipart file uploads, allowing unauthenticated attackers to upload crafted JSP files outside of intended directories using path traversal. Successful exploitation enables remote code execution as the uploaded file can be accessed and executed through the web server.

EPSS 15.40% · 96.7th percentile

Risk Scores

CVSS 4.0
10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score
15.40%
96.7th percentile

Affected Products

VendorProductVersions
Seeyon (Beijing Zhiyuan Internet Software Co., Ltd.)Zhiyuan OA Web Application System6.0, 7.1sp1, 8.0

Timeline

  • CVE Published
  • Jul 27, 2024 CrowdSec Sighting
  • Aug 1, 2024 CrowdSec Sighting
  • Aug 10, 2024 CrowdSec Sighting
  • Aug 15, 2024 CrowdSec Sighting
  • Oct 1, 2024 CrowdSec Sighting
  • Oct 8, 2024 CrowdSec Sighting
  • Jan 25, 2025 CrowdSec Sighting
  • Feb 10, 2025 CrowdSec Sighting
  • Mar 2, 2025 CrowdSec Sighting
  • Mar 5, 2025 CrowdSec Sighting
  • Mar 9, 2025 CrowdSec Sighting
Open in Interactive Console →
$ Console Community · 100/wk Open console ›