Yonyou YonBIP
cpe:2.3:a:yonyou:yonbip:*:*:*:*:*:*:*
- YonYouBip-数据应用服务,2024930
A path traversal vulnerability has been identified in Yonyou YonBIP versions through 3, within the LoginWithV8 interface of the data application service system. This vulnerability allows unauthorized access to sensitive information by improperly handling path references, which can be exploited by traversing directory structures.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including exposure of admin account tokens, within the affected system.
To reproduce this vulnerability, send a GET request to the LoginWithV8 interface with a ticket parameter that includes path traversal sequences, such as '../' symbols. This will bypass directory restrictions and access sensitive files, like the Windows win.ini file. The response will confirm the successful exploitation by displaying the contents of the accessed file.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.