Yonyou YonBIP Path Traversal Vulnerability Allowing Arbitrary File Read
Vulnerability
A path traversal vulnerability allowing arbitrary file reading has been identified in Yonyou YonBIP MA2.7. The issue arises in the FileInputStream function within the '/mobsm/common/userfile' interface. The vulnerability is caused by insufficient validation of the 'path' parameter, which can be manipulated to traverse directories and access sensitive files on the server. This vulnerability can be exploited remotely.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server.
Reproduction
To reproduce this vulnerability, send a GET request to the '/mobsm/common/userfile' endpoint with a crafted 'path' parameter that includes directory traversal sequences. This will bypass the application's file access restrictions and allow the retrieval of arbitrary files from the server.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
