CVE-2025-34163는 Qingdao Dongsheng Weiye Software Co., Ltd. Dongsheng Logistics Software에서 확인된 긴급 등급 보안 취약점입니다. 공개 데이터에 표시된 영향 버전은 <= pre-July 2025 builds입니다. CVSS 기본 점수는 10점입니다. 현재 CISA KEV 등록은 확인되지 않았습니다.
CVE-2025-34163는 Qingdao Dongsheng Weiye Software Co., Ltd. Dongsheng Logistics Software에서 확인된 긴급 등급 보안 취약점입니다. 공개 데이터에 표시된 영향 버전은 <= pre-July 2025 builds입니다. CVSS 기본 점수는 10점입니다. 현재 CISA KEV 등록은 확인되지 않았습니다.
NVD 영문 원문의 세부 내용은 한국어 설명으로 순차 보강 중입니다. 보강 전에는 제품·위험도·실제 악용 여부처럼 공개 데이터로 확인된 정보만 표시합니다.
영문 원문 보기
Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation and access control. An attacker can upload arbitrary files, including executable scripts such as .ashx, via a crafted multipart/form-data POST request. This allows remote code execution on the server, potentially leading to full system compromise. The vulnerability is presumed to affect builds released prior to July 2025 and is remediated in newer versions of the product, though the exact affected range remains undefined. Exploitation evidence w...
영향 제품·버전
제품 Qingdao Dongsheng Weiye Software Co., Ltd. Dongsheng Logistics Software
영향 버전 Qingdao Dongsheng Weiye Software Co., Ltd. Dongsheng Logistics Software <= pre-July 2025 builds
필드별 과거 원문을 추정하지 않습니다. 각 시점의 현재 값과 공식 출처를 대조해 변경 여부를 확인하세요.
기술 정보
CVSS 벡터 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X