RULE(RULE ID:339194)

Rule General Information
Release Date: 2025-06-25
Rule Name: Yonyou NC grouptemplet Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Yoniu NC is a suite of management software products developed by Yoniu Corporation for large enterprises and corporate groups. This product series is built on the latest global internet technologies, cloud computing, and mobile application technologies, designed to help enterprises innovate management models and drive business transformation. The filename parameter in the Yoniu NC /uapim/upload/grouptemplet interface has a directory traversal vulnerability that leads to arbitrary file upload. Attackers can upload script files containing malicious code to the server, enabling them to execute arbitrary system commands and thereby gain control of the server.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.