Impact
The vulnerability is located in the uploadFileToIIS routine of the BaseHandler.ashx endpoint used by Shandong Hoteam InforCenter PLM. Manipulating the File parameter allows an attacker to upload any file, regardless of type, to the web server. This can expose sensitive data or place malicious payloads in a location accessible to web clients, creating a potential vector for further compromise. The flaw permits remote attackers to initiate the upload through standard HTTP requests, and public exploit code is available.
Affected Systems
All installations of Shandong Hoteam InforCenter PLM with versions up to and including 8.3.8 are affected. The BaseHandler.ashx upload endpoint is the entry point for the problem.
Risk and Exploitability
The reported severity rating is moderate to high. A publicly available exploit indicates that the attack can be performed remotely by sending a crafted request. Although no detailed exploit probability score is published, the combination of a moderate severity score and an available exploit suggests a realistic threat. The vulnerability is not listed in any known exploited catalog, but the ability to upload arbitrary files remains a serious risk to confidentiality, integrity, and availability of the affected systems.
OpenCVE Enrichment