Showing 2 vulnerabilities on this page for YonBIP

Signals CISA KEV Ransomware Nuclei
Yonyou vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to path traversal, allowing unauthorized access to sensitive information within the system

CWE-22Jan 9, 20261 related artifact
CVSS7.5v3.1EPSS1.45%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Yonyou YonBIP userfile FileInputStream path traversal

A vulnerability was found in Yonyou YonBIP MA2.7. It has been declared as problematic. Affected by this vulnerability is the function FileInputStream of the file /mobsm/common/userfile. The manipulation of the argument path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE-22Apr 14, 2025
CVSS5.3v4.0EPSS0.559%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX