Seeyon Zhiyuan OA Web Application System Path Traversal Vulnerability in ZIP File Handler
Vulnerability
A path traversal vulnerability has been identified in Seeyon Zhiyuan OA Web Application System version 8.1 SP2. The issue arises in the ZIP File Handler component, specifically within the Download function of the M3CoreController class, located in the seeyon-apps-m3.jar file. The vulnerability allows for remote exploitation by manipulating the Name argument, potentially leading to unauthorized access to files on the server.
Impact
Exploitation of this vulnerability allows for path traversal, which could be used to access sensitive files on the server outside of the intended directory.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
0.8exploitability
5.2remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
