CVE-2024-42676
https://notcve.org/view.php?id=CVE-2024-42676
15 Aug 2024 — File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary code via the /nssys/common/Upload. Aspx? Action=DNPageAjaxPostBack component • https://github.com/WarmBrew/web_vul/blob/main/HZ-cve/HZupload.md • CWE-434: Unrestricted Upload of File with Dangerous Type •
CVE-2024-42677
https://notcve.org/view.php?id=CVE-2024-42677
15 Aug 2024 — An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component • https://github.com/WarmBrew/web_vul/blob/main/HZ-cve/HZlfi.md • CWE-922: Insecure Storage of Sensitive Information •