CVE Database
/

CVE-2025-34163

Back to search

CVE-2025-34163

Published: Aug 27, 2025

Modified: May 26, 2026

PUBLISHED

Description

Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation and access control. An attacker can upload arbitrary files, including executable scripts such as .ashx, via a crafted multipart/form-data POST request. This allows remote code execution on the server, potentially leading to full system compromise. The vulnerability is presumed to affect builds released prior to July 2025 and is remediated in newer versions of the product, though the exact affected range remains undefined. Exploitation evidence was first observed by the Shadowserver Foundation on 2025-07-23 UTC.

VendorProductVersions

Qingdao Dongsheng Weiye Software Co., Ltd.

Dongsheng Logistics Software

affected
0 - <= pre-July 2025 builds

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now