CVE-2026-1218

MEDIUM

Bjskzy Zhiyou ERP <11.0 - XML External Entity Reference

Title source: llm
STIX 2.1

Description

A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the function initRCForm of the file RichClientService.class of the component com.artery.richclient.RichClientService. Performing a manipulation results in xml external entity reference. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

References (4)

Core 4
Core References
Permissions Required, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.341908
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.341908
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.735201

Scores

CVSS v3 6.3
EPSS 0.0022
EPSS Percentile 13.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-610 CWE-611
Status published
Products (1)
Bjskzy/Zhiyou ERP 11.0
Published Jan 20, 2026
Tracked Since Feb 18, 2026