CVE-2024-46088: Zhejiang University Entersoft Customer Resource Management

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An arbitrary file upload vulnerability in the ProductAction.entphone interface of Zhejiang University Entersoft Customer Resource Management System v2002 to v2024 allows attackers to execute arbitrary code via uploading a crafted file.

Affected products

  • Zhejiang University Entersoft Customer Resource Management: from 2002, up to and including 2024

Published 2024-10-11. Last modified 2026-07-05.