Description
A vulnerability was identified in zlt2000 microservices-platform up to 6.0.0. Affected by this vulnerability is the function Upload of the file zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Es geht um die Funktion Upload der Datei zlt-business/file-center/src/main/java/com/central/file/controller/FileController.java. Dank Manipulation mit unbekannten Daten kann eine unrestricted upload-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Product status
Timeline
2025-08-10: | Advisory disclosed |
2025-08-10: | VulDB entry created |
2025-08-10: | VulDB entry last update |
Credits
ZAST.AI (VulDB User)
References
vuldb.com/?id.319375 (VDB-319375 | zlt2000 microservices-platform FileController.java upload unrestricted upload)
vuldb.com/?ctiid.319375 (VDB-319375 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.623100 (Submit #623100 | zlt2000 https://github.com/zlt2000/microservices-platform <=6.0.0 Unrestricted Upload of File with Dangerous Type (CWE-434))
github.com/zlt2000/microservices-platform/issues/77
github.com/zlt2000/microservices-platform/issues/77