Yonyou U9 Unauthenticated File Upload Scanner
Targets the PatchFile.asmx endpoint to upload arbitrary files without authentication, enabling remote code execution on Yonyou U9 ERP systems.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
13 days 13 hours
Scan only one
Domain, Subdomain, IPv4
Toolbox
Yonyou U9 is an integrated enterprise resource planning (ERP) software widely used by medium to large-sized businesses in manufacturing, trading, and service sectors. It streamlines accounting, inventory, production, and other operational processes, making it a critical component of corporate IT infrastructure. Users depend on its robust modules for seamless data integration and business optimization.
The vulnerability is an unauthenticated arbitrary file upload flaw in the PatchFile.asmx web service. It arises due to insufficient validation of file upload requests, allowing attackers to bypass authentication checks. This weakness stems from missing access controls and lack of file type verification, enabling malicious file uploads without any credentials.
Specifically, the vulnerable endpoint is PatchFile.asmx, which handles file uploads for patching purposes. Attackers can send crafted HTTP POST requests to this endpoint with arbitrary file content, such as web shells or executable scripts. The absence of authentication and input sanitization makes it possible to upload files that can be executed on the server.
If exploited, an attacker can achieve remote code execution on the Yonyou U9 server, leading to full system compromise. This can result in data theft, ransomware deployment, or lateral movement within the network. Given the critical CVSS score of 9.0, immediate remediation is essential to prevent severe business disruption and financial loss.