zzskzy Warehouse Refinement Management System Unrestricted File Upload Vulnerability

Vulnerability

A critical vulnerability allowing unrestricted file uploads has been identified in zzskzy Warehouse Refinement Management System version 1.3. The issue arises in the UploadCrash function within the file /crash/log/SaveCrash.ashx, where the manipulation of the file argument enables remote exploitation. This vulnerability could lead to the upload of malicious files that are automatically processed in the product's environment.

Impact

Exploitation of this vulnerability allows for unrestricted file uploads, which could be used to upload malicious files that are executed or processed by the application, potentially leading to further attacks such as remote code execution.

Reproduction

The vulnerability can be reproduced by sending a request to the /crash/log/SaveCrash.ashx endpoint with a manipulated file argument that bypasses any file type restrictions. This can be done remotely.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.