CNVD-2023-96945: McVie Safety Digital Management Platform - Arbitrary File Upload

日期: 2025-08-01 | 影响软件: McVie Safety Digital Management Platform | POC: 已公开

漏洞描述

Jiangsu Maiwei Intelligent Technology Co., Ltd. is a software technology service provider focusing on customized development of software products. There is a file upload vulnerability in Jiangsu Maiwei Intelligent Technology Co., Ltd.'s safe production digital management platform. An attacker can use this vulnerability to gain server permissions.

PoC代码[已公开]

id: CNVD-2023-96945

info:
  name: McVie Safety Digital Management Platform - Arbitrary File Upload
  author: DhiyaneshDk
  severity: high
  description: |
    Jiangsu Maiwei Intelligent Technology Co., Ltd. is a software technology service provider focusing on customized development of software products. There is a file upload vulnerability in Jiangsu Maiwei Intelligent Technology Co., Ltd.'s safe production digital management platform. An attacker can use this vulnerability to gain server permissions.
  reference:
    - https://blog.csdn.net/weixin_42628854/article/details/136036109
  metadata:
    verified: true
    max-request: 1
    fofa-query: "安全生产数字化管理平台"
  tags: cnvd,cnvd2023,file-upload,mcvie,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/Content/Plugins/uploader/FileChoose.html"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "选择文件"
          - "提交"
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a004730450221009cbaeedc386a69b34f7a408160f002d985aa2aa75850bb833964061c865402ce0220256332a577351c2d6294795ea7bd173cf61085141346faa30aac9efc6bfb3c68:922c64590222798bb761d5b6d8e72950

相关漏洞推荐