CVE-2023-7334

Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation as early as 2023-08-19 (UTC).
Configurations

Configuration 1 (hide)

cpe:2.3:a:chanjetvip:t\+:*:*:*:*:*:*:*:*

History

17 Jun 2026, 06:52

Type Values Removed Values Added
Summary
  • (es) Las versiones de Changjetong T+ hasta la 16.x inclusive contienen una vulnerabilidad de deserialización de .NET en un endpoint de AjaxPro que puede conducir a la ejecución remota de código. Un atacante remoto puede enviar una solicitud manipulada a /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore con un cuerpo JSON malicioso que aprovecha la deserialización de tipos .NET controlados por el atacante para invocar métodos arbitrarios como System.Diagnostics.Process.Start. Esto puede resultar en la ejecución de comandos arbitrarios en el contexto de la cuenta de servicio de la aplicación T+. La Shadowserver Foundation observó evidencia de explotación tan pronto como el 19 de agosto de 2023 (UTC).

23 Jan 2026, 19:51

Type Values Removed Values Added
CPE cpe:2.3:a:chanjetvip:t\+:*:*:*:*:*:*:*:*
First Time Chanjetvip
Chanjetvip t\+
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://blog.csdn.net/qq_53003652/article/details/134031230 - () https://blog.csdn.net/qq_53003652/article/details/134031230 - Exploit, Third Party Advisory
References () https://blog.csdn.net/u010025272/article/details/131553591 - () https://blog.csdn.net/u010025272/article/details/131553591 - Exploit, Third Party Advisory
References () https://github.com/MD-SEC/MDPOCS/blob/main/ChangJieTongTPlus_GetStoreWarehouseByStore_Rce_Poc.py - () https://github.com/MD-SEC/MDPOCS/blob/main/ChangJieTongTPlus_GetStoreWarehouseByStore_Rce_Poc.py - Product
References () https://www.chanjetvip.com/product/goods/detail?id=6077e91b70fa071069139f62 - () https://www.chanjetvip.com/product/goods/detail?id=6077e91b70fa071069139f62 - Release Notes
References () https://www.freebuf.com/articles/web/381731.html - () https://www.freebuf.com/articles/web/381731.html - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/changjetong-tplus-getstorewarehousebystore-deserialization-rce - () https://www.vulncheck.com/advisories/changjetong-tplus-getstorewarehousebystore-deserialization-rce - Third Party Advisory

21 Jan 2026, 22:15

Type Values Removed Values Added
Summary (en) Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation on 2023-08-19 (UTC). (en) Changjetong T+ versions up to and including 16.x contain a .NET deserialization vulnerability in an AjaxPro endpoint that can lead to remote code execution. A remote attacker can send a crafted request to /tplus/ajaxpro/Ufida.T.CodeBehind._PriorityLevel,App_Code.ashx?method=GetStoreWarehouseByStore with a malicious JSON body that leverages deserialization of attacker-controlled .NET types to invoke arbitrary methods such as System.Diagnostics.Process.Start. This can result in execution of arbitrary commands in the context of the T+ application service account. Exploitation evidence was observed by the Shadowserver Foundation as early as 2023-08-19 (UTC).

20 Jan 2026, 16:16

Type Values Removed Values Added
References () https://www.freebuf.com/articles/web/381731.html - () https://www.freebuf.com/articles/web/381731.html -

15 Jan 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 22:16

Updated : 2026-06-17 06:52


NVD link : CVE-2023-7334

Mitre link : CVE-2023-7334

CVE.ORG link : CVE-2023-7334


JSON object : View

Products Affected

chanjetvip

  • t\+
CWE
CWE-502

Deserialization of Untrusted Data