Vulnerabilities
Vulnerable Software
Yeqifu:  Security Vulnerabilities
Warehouse Management System 1.2 contains an authenticated arbitrary file deletion vulnerability. The /goods/deleteGoods endpoint accepts a user-controlled goodsimg parameter, which is directly concatenated with the server's UPLOAD_PATH and passed to File.delete() without validation. A remote authenticated attacker can delete arbitrary files on the server by supplying directory traversal payloads.
CVSS Score
8.1
EPSS Score
0.004
Published
2025-12-05
The warehouse management system version 1.2 contains an arbitrary file read vulnerability. The endpoint `/file/showImageByPath` does not sanitize user-controlled path parameters. An attacker could exploit directory traversal to read arbitrary files on the server's file system. This could lead to the leakage of sensitive system information.
CVSS Score
7.5
EPSS Score
0.003
Published
2025-12-05


Contact Us

Shodan ® - All rights reserved