Bjskzy Zhiyou ERP Path Traversal Vulnerability in File Upload Function

Vulnerability

A path traversal vulnerability has been identified in Bjskzy Zhiyou ERP versions prior to 11.0. The issue resides in the 'uploadStudioFile' function of the 'com.artery.form.services.FormStudioUpdater' component. This vulnerability allows remote exploitation by manipulating the 'filepath' argument, leading to unauthorized file access. The vulnerability has been publicly disclosed, and the vendor has not responded to initial contact regarding the issue.

Impact

Exploitation of this vulnerability allows for arbitrary file upload, which could be used to execute malicious code or overwrite existing files, depending on the application's file handling procedures.

Reproduction

To reproduce this vulnerability, upload a file through the 'uploadStudioFile' interface, ensuring that the 'filepath' parameter is manipulated to include directory traversal sequences. The uploaded file should be in XML format to bypass the application's file type restrictions. Once uploaded, the file can be accessed from the specified traversal path, potentially leading to code execution if the file is processed by the application.

Added: Sep 29, 2025, 4:18 AM
Updated: Sep 29, 2025, 4:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
0.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.