CVE-2024-13984

Executive Summary

QiAnXin TianQing Management Center up to 6.7.0.4130 has an unauthenticated path‑traversal flaw in the rptsvr/upload endpoint. The filename field in multipart form‑data is not sanitized, letting attackers upload files to arbitrary server locations, including web‑accessible directories. This can lead to remote code execution. Shadowserver Foundation first observed exploitation on 2024‑08‑23 UTC. No CISA KEV listing yet.


Authoritative CVE Metadata - CVSS Base Score: Unknown (Unknown) - Published: 2025-08-27T22:15:33.777 - Last Modified: 2026-09-26T21:10:00.130

Original Description: QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attackers to upload files to arbitrary locations on the server. The /rptsvr/upload endpoint fails to sanitize the filename parameter in multipart form-data requests, enabling path traversal. This allows attackers to place executable files in web-accessible directories, potentially leading to remote code execution. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-08-23 UTC.

"The bird of paradise alights only upon the hand that does not grasp."

— John Berry
Source: NVD