RULE(RULE ID:338789)

Rule General Information
Release Date: 2025-04-08
Rule Name: Huizhi Erp API filehandle.aspx Arbitrary File Read Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Huizhi ERP is an enterprise resource planning software developed by Jiangyin Huizhi Software Technology Co., LTD., aiming to help enterprises optimize business processes, improve management efficiency and enhance comprehensive competitiveness by means of information technology. ERP filehandle.aspx Any file reading vulnerability on the interface. Unauthenticated attackers can use this vulnerability to read the internal configuration file of the system, resulting in information leakage.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.