[Security Advisory] Matricloud Public Directory File Download Restriction Missing Vulnerability (ZTSA-202504-000001)
Release time:2026.08.06
Return list
Product:Matricloud
CVEID:/
Advisory ID:ZTSA-202504-000001
Severity:Medium
Date:2026.08.06
CVEID:/
Advisory ID:ZTSA-202504-000001
Severity:Medium
Date:2026.08.06
Description
The file download module of Matricloud has a path validation logic flaw. When processing specific static resource requests, the system does not strictly restrict the file path suffix and directory scope. Attackers can exploit this logic to construct specific requests and download non-sensitive public files such as default product manuals or sample images from system directories. Although this vulnerability cannot read system configuration files or user private data, it violates the principle of secure access control.
Affected Versions
• Affected: Matricloud version 2.2.0.
• Not Affected: Matricloud version 2.2.3 and higher have fixed this issue.
Vulnerability Score
ZTSA-202504-000001:
CVSS:5.3/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The score is based on the CVSS 3.1 standard. The scoring criteria can be referenced at (https://www.first.org/cvss/calculator/3.1)
Mitigation and Remediation Measures
• Remediation: Shanghai Chint Power Systems Co., Ltd. has completed the seamless upgrade of the Matricloud service through the cloud platform.
• User Action: No action is required from customers. The platform has been updated to the fixed version 2.2.3, and the service is unaffected.
• Temporary Fix: Not applicable (the platform has been uniformly fixed).
Acknowledgments
Shanghai Chint Power Systems Co., Ltd. thanks the internal security team for discovering this logic issue during a routine code audit.
Contact Information
For security issues related to Shanghai Chint Power Systems Co., Ltd.'s products and solutions, please report to psirt@chint.com
Revision History
Version:V1.0
Date:2025-04-05
Description:Initial Release
Statement
All software updates, patches, and documentation provided by Shanghai Chint Power Systems Co., Ltd. are proprietary works of Chint Power. These materials may only be used for product maintenance and security improvements. Any unauthorized modification, distribution, decompilation, or reverse engineering is strictly prohibited.
Chint Power makes no express or implied warranties regarding the information provided, including but not limited to warranties of merchantability, fitness for a particular purpose, or non-infringement. Chint Power shall not be liable for any direct, indirect, incidental, or consequential damages arising from the use of this document or related software.
Chint Power reserves the right to update or modify this document at any time without prior notice. Customers are responsible for implementing security updates in a timely manner to protect their systems.
English
简体中文
Italiano
Polski
Español
Deutsch
Türkiye
Дистриб'ютори в Україні
United States
Brasileiro
Chile
日本語



沪ICP备10211377号-1