jshERP v3.3 is vulnerable to Arbitrary File Upload. The jshERP-boot/systemConfig/upload interface does not check the uploaded file type, and the biz parameter can be spliced into the upload path, resulting in arbitrary file uploads with controllable paths.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-02-06T00:00:00

Updated: 2024-08-01T23:13:08.566Z

Reserved: 2024-01-25T00:00:00

Link: CVE-2024-24000

cve-icon Vulnrichment

Updated: 2024-08-01T23:13:08.566Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-06T16:15:52.317

Modified: 2024-02-13T20:30:10.053

Link: CVE-2024-24000

cve-icon Redhat

No data.