RULE(RULE ID:330915)

Rule General Information
Release Date: 2020-08-25
Rule Name: SEEYON OA Software Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: SEEYON OA Software is a Chinese collaborative management software developer and service provider focusing on the field of collaborative management software, integrating product development, market expansion, channel sales, and technical support. In Zhiyuan A8+ and other versions, there is a remote arbitrary file upload file upload vulnerability, and it can be triggered without logging in. Attackers can use this vulnerability to remotely send carefully constructed website backdoor files without authorization to obtain the target server> permissions, and execute arbitrary code on the target server.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows
Reference:
Solutions
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.