An issue in Wanxing Technology's Yitu project Management Software 3.2.2 allows a remote attacker to execute arbitrary code via the platformpluginpath parameter to specify that the qt plugin loads the directory.
https://gist.github.com/zty-1995/3fcdf702017ad6721e5011f74c1f6cee