<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>EBA Plus Document and Workflow Management System (6.7.141 - 10.0.10) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/eba-plus-document-and-workflow-management-system-6.7.141---10.0.10/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 28 Sep 2026 10:15:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/eba-plus-document-and-workflow-management-system-6.7.141---10.0.10/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unrestricted File Upload Vulnerability in eBA Plus</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85134/</link><pubDate>Mon, 28 Sep 2026 10:15:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-85134/</guid><description>An unrestricted file upload vulnerability in Bimser Solution Software Trade Inc. eBA Plus Document and Workflow Management System allows unauthenticated attackers to execute arbitrary code via web shell deployment.</description><content:encoded><![CDATA[<p>CVE-2026-85134 identifies a critical security flaw in Bimser Solution Software Trade Inc. eBA Plus Document and Workflow Management System, specifically affecting versions 6.7.141 through 10.0.10. The vulnerability stems from improper validation of user-supplied files during the upload process. An unauthenticated attacker can exploit this weakness to upload executable scripts, such as web shells, directly to the web server's directory. Once the malicious file is uploaded, the attacker can trigger its execution by requesting the file path via the web server. Successful exploitation results in remote code execution (RCE) with the privileges of the web application service account. This allows for total system compromise, data exfiltration, or the establishment of persistent backdoors within the organization's environment. Defenders should prioritize patching affected instances to version 10.0.11 or later.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a high risk to organizations utilizing eBA Plus for document and workflow management. Exploitation allows unauthenticated attackers to gain remote code execution, leading to potential unauthorized access to sensitive documents, workflow metadata, and underlying server infrastructure. If exploited, an attacker could maintain persistent access to the system, modify corporate workflows, or exfiltrate intellectual property. No specific victim count is documented, but the nature of the software makes it a target for attackers seeking access to sensitive enterprise data.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Patch eBA Plus Document and Workflow Management System to version 10.0.11 or later immediately.</li>
<li>Audit web server upload directories for unauthorized script files (e.g., .aspx, .php, .jsp) created by the web application service account.</li>
<li>Restrict write permissions on the web server directory to prevent the execution of files uploaded to temporary or user-accessible paths.</li>
<li>Monitor web server logs for suspicious POST requests to document upload endpoints that result in 200 OK statuses or contain unexpected file extensions.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>web-application</category></item></channel></rss>