Executive brief
Global IT Informatics Services Inc. WEOLL, a business process management platform, contains a security flaw that allows users to upload dangerous file types. This vulnerability could allow an attacker to bypass access controls and perform unauthorized actions within the system. Successful exploitation could lead to the theft of sensitive business data or unauthorized modification of system settings.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in Global IT Informatics Services Inc. WEOLL versions 2.0.9 through 3.2.45.32. The flaw allows an authenticated attacker with low privileges to upload malicious files, which can subsequently be used to access restricted functionalities that are not properly protected by Access Control Lists (ACLs). The attack requires network connectivity and minimal user interaction. This can result in a high impact on data confidentiality and integrity. Users are advised to upgrade to version 3.2.45.33 or later to remediate the issue.
Affected products
- Global IT Informatics Services Inc. WEOLL from 2.0.9 before 3.2.45.33
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory