References https://www.cnblogs.com/pursue-security/p/17685157.html https://www.cnvd.org.cn/flaw/show/CNVD-2020-61867 https://stack.chaitin.com/poc/detail/1012 https://www.secevery.com/toBugInfo?id=1806106385696595970 https://blog.csdn.net/weixin_61496153/article/details/144418509 https://www.cnblogs.com/limanman233/p/18489683 https://cn-sec.com/archives/2594614.html https://qkl.seebug.org/vuldb/ssvid-93332 https://mrxn.net/jswz/yonyou-ncc-LfwFileUploadServlet-rce.html https://nosec.org/m/share/4472.html https://www.ihonker.com/thread-33379-1-1.html https://avd.aliyun.com/detail?id=AVD-2024-1764977 https://www.saury.net/1267.html https://github.com/adysec/POC/blob/main/wpoc/%E7%94%A8%E5%8F%8BOA/%E7%94%A8%E5%8F%8BNC%E7%B3%BB%E7%BB%9F%E6%8E%A5%E5%8F%A3yerfile_down%E5%AD%98%E5%9C%A8SQL%E6%B3%A8%E5%85%A5%E6%BC%8F%E6%B4%9E.md https://blog.csdn.net/qq_36334672/article/details/136507335 https://cloud.tencent.com/developer/article/2443503 https://www.rsrx.net/yongyou/5912.html https://nvd.nist.gov/vuln/detail/CVE-2025-34039 https://s4e.io/tools/yonyou-ufida-nc-information-disclosure
Related Vulnerabilities畅捷通T+ERP系统Ufida.T.SM.FC.UIP接口处存在反序列化漏洞畅捷通T+ /tplus/ajaxpro/Ufida.T.SM.UIP.MultiCompanySettingController.Ufida.T.SM.UIP.ashx SQL 注入漏洞yonyou-ufida-oa-uapws-xxe: 用友 UFIDA OA XXEPoCCVE-2025-2709: Yonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingPoCCVE-2025-2710: Yonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingPoCCVE-2025-2711: Yonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingPoCCVE-2025-2712: Yonyou UFIDA ERP-NC V5.0 - Cross-Site ScriptingPoCCVD-2023-3118: 用友 UFIDA ActionHandlerServlet 反序列化漏洞PoCyonyou-ufida-ksoa-image-upload-file: 用友-时空KSOA ImageUpload 任意文件上传PoCCNVD-2021-30167: UFIDA NC BeanShell Remote Command ExecutionPoCCNVD-C-2023-76801: UFIDA NC uapjs - Remote Code ExecutionPoCCNVD-2024-33023: UFIDA U8 Cloud - SQL InjectionPoCchanjet-tplus-fileupload: UFIDA Chanjet TPluse Upload.aspx - Arbitrary File Upload