CVE-2025-66744
- EPSS 1.45%
- Veröffentlicht 09.01.2026 17:15:52
- Zuletzt bearbeitet 15.04.2026 00:35:42
In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system
CVE-2025-3562
- EPSS 0.57%
- Veröffentlicht 14.04.2025 10:31:06
- Zuletzt bearbeitet 15.04.2026 00:35:42
A vulnerability was found in Yonyou YonBIP MA2.7. It has been declared as problematic. Affected by this vulnerability is the function FileInputStream of the file /mobsm/common/userfile. The manipulation of the argument path leads to path traversal. T...
CVE-2023-51906
- EPSS 0.97%
- Veröffentlicht 20.01.2024 02:15:07
- Zuletzt bearbeitet 09.07.2026 01:18:48
An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component.
CVE-2023-51924
- EPSS 0.76%
- Veröffentlicht 20.01.2024 02:15:07
- Zuletzt bearbeitet 09.07.2026 01:18:48
An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2023-51925
- EPSS 0.76%
- Veröffentlicht 20.01.2024 02:15:07
- Zuletzt bearbeitet 09.07.2026 01:18:49
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2023-51928
- EPSS 0.76%
- Veröffentlicht 20.01.2024 01:15:08
- Zuletzt bearbeitet 09.07.2026 01:18:49
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2023-51926
- EPSS 0.5%
- Veröffentlicht 20.01.2024 01:15:07
- Zuletzt bearbeitet 09.07.2026 01:18:49
YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.
CVE-2023-51927
- EPSS 0.55%
- Veröffentlicht 20.01.2024 01:15:07
- Zuletzt bearbeitet 09.07.2026 01:18:49
YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.