Vulnerability CVE-2024-46088


Published: 2024-10-11

Description:
An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute arbitrary code via uploading a crafted file.

 References:
http://zhejiang.com
https://periwinkle-brother-031.notion.site/Analysis-of-any-file-upload-vulnerability-of-Zhejiang-University-Entersoft-Customer-Resource-Managem-0f88a0e77d6f4f638bc3c4e508a1e0ed
https://www.entersoft.cn/

Copyright 2026, cxsecurity.com

 

Back to Top