Changjetong T+ <= 16.x GetStoreWarehouseByStore Deserialization RCE
Published Jan 15, 2026
9.3
CRITICALCVSS 4.0
EPSS 1.11%
Description
Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation as early as 2023-08-19 (UTC).
Affected products
-
- Version 0StatusaffectedConstraints<=16.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Changjetong Information Technology Co., Ltd. | n/a | n/a |
|
- ≤ 16.000.000.0283
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://blog.csdn.net/qq_53003652/article/details/134031230 exploitThird Party Advisory
- https://blog.csdn.net/u010025272/article/details/131553591 exploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-60535 Advisory
- https://github.com/MD-SEC/MDPOCS/blob/main/ChangJieTongTPlus_GetStoreWarehouseByStore_Rce_Poc.py exploitProduct
- https://www.chanjetvip.com/product/goods/detail?id=6077e91b70fa071069139f62 release-notespatchRelease Notes
- https://www.freebuf.com/articles/web/381731.html exploitThird Party Advisory
- https://www.vulncheck.com/advisories/changjetong-tplus-getstorewarehousebystore-deserialization-rce third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog.csdn.net/qq_53003652/article/details/134031230 | exploitThird Party Advisory | |
| https://blog.csdn.net/u010025272/article/details/131553591 | exploitThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-60535 | Advisory | |
| https://github.com/MD-SEC/MDPOCS/blob/main/ChangJieTongTPlus_GetStoreWarehouseByStore_Rce_Poc.py | exploitProduct | |
| https://www.chanjetvip.com/product/goods/detail?id=6077e91b70fa071069139f62 | release-notespatchRelease Notes | |
| https://www.freebuf.com/articles/web/381731.html | exploitThird Party Advisory | |
| https://www.vulncheck.com/advisories/changjetong-tplus-getstorewarehousebystore-deserialization-rce | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.