'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/29
Rule Name:Glodon OA Arbitrary File Create Vulnerability
Severity:high
CVE ID:
| Descripiton:
|
Glodon OA is a digital office platform specially built for the construction industry, which integrates process approval, project collaboration and data integration to help enterprises manage efficiently. Glodon OA has an arbitrary file creation vulnerability. An attacker can use the vulnerability to create a file on the server, and then use another vulnerability to write malicious code in the newly created file, so as to achieve remote code execution. This rule supports to defend the A6: Vulnerabe and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.