2 results (0.004 seconds)

CVSS: 9.0EPSS: 0%CPEs: 2EXPL: 0

15 Aug 2024 — File Upload vulnerability in Huizhi enterprise resource management system v.1.0 and before allows a remote attacker to execute arbitrary code via the /nssys/common/Upload. Aspx? Action=DNPageAjaxPostBack component • https://github.com/WarmBrew/web_vul/blob/main/HZ-cve/HZupload.md • CWE-434: Unrestricted Upload of File with Dangerous Type •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

15 Aug 2024 — An issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nssys/common/filehandle. Aspx component • https://github.com/WarmBrew/web_vul/blob/main/HZ-cve/HZlfi.md • CWE-922: Insecure Storage of Sensitive Information •