RULE(RULE ID:338452)

Rule General Information
Release Date: 2024-10-09
Rule Name: WANHU OA fileupload.controller Aribitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Wanhu OA is a software that integrates multiple office automation functions, supporting document management, transaction approval, knowledge management, etc. It also provides mobile office applications to help enterprises improve operational efficiency and employees' office experience. Wanhu OA/defaultroot/upload/fileUpload.cntroller arbitrary file upload vulnerability allows attackers to upload malicious files to the server, which may lead to remote code execution, website tampering, or other forms of attacks, seriously threatening system and data security.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.