---
id: CVE-2025-11139
title: A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0
summary: >-
  A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is
  the function uploadStudioFile of the component
  com.artery.form.services.FormStudioUpdater. This manipulation of the argument
  filepath causes path traversal. Remo…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-22
vendor: zhiyou-group
product: zhiyou_erp
affected:
  - zhiyou_erp <= 11.0
published: '2025-09-29'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T09:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11139'
references:
  - url: >-
      https://github.com/FightingLzn9/vul/blob/main/%E6%97%B6%E7%A9%BA%E6%99%BA%E5%8F%8Berp-2.md
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?ctiid.326216'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?id.326216'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/?submit.658077'
    label: cna@vuldb.com
tags:
  - nvd
epss: 0.00733
epssPercentile: 0.52957
ingestedAt: '2026-10-09T09:31:00.979Z'
---

## Overview

A vulnerability was determined in Bjskzy Zhiyou ERP up to 11.0. Affected is the function uploadStudioFile of the component com.artery.form.services.FormStudioUpdater. This manipulation of the argument filepath causes path traversal. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected

- `zhiyou_erp <= 11.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
