Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2023-51925
Disclosure Date: January 20, 2024 (last updated February 26, 2025)
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown
CVE-2023-51924
Disclosure Date: January 20, 2024 (last updated February 26, 2025)
An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown
CVE-2023-51906
Disclosure Date: January 20, 2024 (last updated January 27, 2024)
An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a crafted script to the ServiceDispatcherServlet uap.framework.rc.itf.IResourceManager component.
0
Attacker Value
Unknown
CVE-2023-51928
Disclosure Date: January 20, 2024 (last updated February 26, 2025)
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown
CVE-2023-51927
Disclosure Date: January 20, 2024 (last updated February 26, 2025)
YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou.hrcloud.attend.web.AttendScriptController.runScript() method.
0
Attacker Value
Unknown
CVE-2023-51926
Disclosure Date: January 20, 2024 (last updated January 27, 2024)
YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs.framework.comn.serv.CommonServletDispatcher component.
0