RULE(RULE ID:338517)

Rule General Information
Release Date: 2024-11-05
Rule Name: Smartbi imageimport.jsp Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Smartbi is an enterprise-level business intelligence and big data analysis platform developed by Smart Software to meet users' big data analysis needs in enterprise-level reports, data visualization analysis, self-service analysis platform, data mining modeling, AI intelligent analysis and other big data analysis needs. Smartbi V72 V856 and V95. The following version/vision/designer/imageimport JSP page has any file upload loopholes, allow the attacker to upload malicious files to the server, could lead to a remote code execution, website, tampering with or other forms of attack, System and data security are seriously compromised.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.