PT-2025-32456 · Unknown · Qiyuesuo Eelectronic Signature Platform

·

CVE-2025-8775

·

Published

2025-08-09

·

Updated

2025-09-16

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Qiyuesuo Eelectronic Signature Platform versions up to 4.34
Description: A critical issue exists in Qiyuesuo Eelectronic Signature Platform, potentially allowing for unrestricted file uploads. The execute function within the /api/code/upload file of the Scheduled Task Handler component is affected. Manipulation of the File argument can lead to exploitation. The exploit has been publicly disclosed.
Recommendations: Versions prior to 4.34: As a temporary workaround, consider restricting access to the /api/code/upload endpoint until a patch is available. Versions prior to 4.34: Avoid uploading untrusted files through the affected endpoint.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-8775

Affected Products

Qiyuesuo Eelectronic Signature Platform