Executive brief
Yonyou KSOA, a business management software platform, contains a critical security flaw in its image upload component. An unauthorized attacker can exploit this to upload malicious files directly to the server without needing a username or password. If successful, this allows the attacker to take complete control of the system, potentially leading to data theft, service disruption, or further attacks on the corporate network.
Technical details
An unrestricted file upload vulnerability exists in the 'com.sksoft.bill.ImageUpload' servlet of Yonyou KSOA 9.0. The component fails to perform authentication or validate file types, extensions, and content for POST requests. An attacker can leverage the 'filepath' and 'filename' parameters to upload a JSP webshell to the web root (typically under the /pictures/ directory). Once uploaded, the malicious script can be executed by the web server, resulting in unauthenticated remote code execution (RCE) with the privileges of the web service. Evidence of active exploitation was reported as early as November 2023.
Affected products
- Yonyou Network Technology Co., Ltd. KSOA 9.0
Timeline
- 2023-11-07: exploited: Exploitation evidence first observed by Shadowserver Foundation.
- 2026-07-02: advisory: NVD/VulnCheck advisory published.