Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An Arbitrary File Upload issue in the file browser of DIMO YellowBox CRM before 6.3.4 allows a standard authenticated user to deploy a new WebApp WAR file to the Tomcat server via Path Traversal, allowing remote code execution with SYSTEM privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
DIMO YellowBox CRM 代码问题漏洞
Vulnerability Description
DIMO YellowBox CRM 6.3.4之前版本中的文件浏览器存在代码问题漏洞。攻击者可利用漏洞将新的WebApp WAR文件部署到Tomcat服务器,进而使用SYSTEM权限执行代码。
CVSS Information
N/A
Vulnerability Type
N/A