R-SOFT SERWIS DMS是R-SOFT SERWIS公司的一款应用服务器产品。 R-SOFT SERWIS DMS v3.19-2862之前版本和v3.17-2580之前版本存在授权问题漏洞,该漏洞源于不安全的直接对象引用(IDOR),应用程序通过ID从数据库获取文件并仅依赖会话认证服务,可能导致任何有效用户访问任意文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| R-SOFT SERWIS | DMS | < v3.19-2862 |
affected |
< v3.17-2580 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| R-SOFT SERWIS | DMS | 0 ~ v3.19-2862 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-41877 | Stored XSS in R-SOFT DMS | |
| CVE-2026-41880 | OS Command Injection in R-SOFT DMS | |
| CVE-2026-41879 | Weak password hashing in R-SOFT DMS | |
| CVE-2026-41876 | OS Command Injection in R-SOFT DMS |
No comments yet