Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2022-50973: Yonyou KSOA 9.0: Unauthenticated File Upload Allows Remote Code Execution
CVE-2022-50973
CVE-2022-50973
Summary
An attacker can upload malicious files to a Yonyou KSOA 9.0 server without a password, potentially allowing them to execute code on the server. This is a serious risk because it allows unauthorized access. To protect your server, ensure you have the latest security patches installed and monitor your server logs for suspicious activity.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| yonyou network technology co., ltd. | ksoa | 9.0 |
Original title
Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet
Original description
Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticated attackers to upload arbitrary files by submitting a POST request with attacker-controlled filepath and filename parameters without any authentication, file type, extension, or content validation. Attackers can upload a JSP webshell by specifying a malicious filename and root filepath, with the uploaded file stored under the pictures directory and directly executed by the web server, resulting in unauthenticated remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-11-07 (UTC).
nvd CVSS3.1
9.8
nvd CVSS4.0
9.3
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 2 Jul 2026 · Updated: 23 Jul 2026 · First seen: 2 Jul 2026