RULE(RULE ID:338552)

Rule General Information
Release Date: 2024-11-19
Rule Name: Landray EKP hrStaffWebService Arbitrary File Read Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Landray EKP platform is positioned as a new generation of digital ecological OA platform. Digitalization is developing in depth. It is accelerating the construction of the industrial Internet and putting forward higher requirements for enterprise collaboration capabilities. Lanling's new generation of ecological OA platform can support office digitalization and management intelligence., application platform, and organization ecology, empower large and medium-sized organizations to more efficient internal and external collaboration and management, and support business model innovation and transformation development. This vulnerability is caused by the transmission of malicious XML files through the hrStaffWebService interface, which can be read through protocols such as file, causing any file reading vulnerability. Attackers can use this vulnerability to read important system files, such as database configuration files and system configuration files.
Impact: An attacker could exploit the vulnerability to obtain sensitive information from a server.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.