Yonyou YonBIP Path Traversal Vulnerability Allowing Arbitrary File Read

Vulnerability

A path traversal vulnerability allowing arbitrary file reading has been identified in Yonyou YonBIP MA2.7. The issue arises in the FileInputStream function within the '/mobsm/common/userfile' interface. The vulnerability is caused by insufficient validation of the 'path' parameter, which can be manipulated to traverse directories and access sensitive files on the server. This vulnerability can be exploited remotely.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive files on the server.

Reproduction

To reproduce this vulnerability, send a GET request to the '/mobsm/common/userfile' endpoint with a crafted 'path' parameter that includes directory traversal sequences. This will bypass the application's file access restrictions and allow the retrieval of arbitrary files from the server.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.