A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function uploadStudioFile of the component com.artery.form.services.FormStudioUpdater. This manipulation of the argument filepath causes path traversal. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
History

Fri, 03 Oct 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Zhiyou-group
Zhiyou-group zhiyou Erp
CPEs cpe:2.3:a:zhiyou-group:zhiyou_erp:*:*:*:*:*:*:*:*
Vendors & Products Zhiyou-group
Zhiyou-group zhiyou Erp

Mon, 29 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 29 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Bjskzy
Bjskzy zhiyou Erp
Vendors & Products Bjskzy
Bjskzy zhiyou Erp

Mon, 29 Sep 2025 03:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function uploadStudioFile of the component com.artery.form.services.FormStudioUpdater. This manipulation of the argument filepath causes path traversal. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title Bjskzy Zhiyou ERP com.artery.form.services.FormStudioUpdater uploadStudioFile path traversal
Weaknesses CWE-22
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-09-29T11:49:30.691Z

Reserved: 2025-09-28T18:42:27.915Z

Link: CVE-2025-11139

cve-icon Vulnrichment

Updated: 2025-09-29T11:49:24.200Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-29T04:15:38.493

Modified: 2025-10-03T18:19:49.773

Link: CVE-2025-11139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-29T09:29:20Z