CVE-2024-48779: Wanxingtechnology Yitu Project Management Software

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.

Affected products

Published 2024-10-15. Last modified 2026-06-17.