RULE(RULE ID:338220)

Rule General Information
Release Date: 2024-07-02
Rule Name: Qiyuesuo Remote Command Execution Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Qiyuesuo is an electronic contract management tool. It helps enterprises and individuals improve the efficiency and security of contract processing by providing the functions of signing, storing and managing contracts online. There is a remote code execution vulnerability in the Qiyuesuo. An unauthenticated attacker can bypass permission authentication by using tomcat's improper path parameter parsing feature to execute malicious code on the target server and obtain server permissions.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.