An issue in Wanxing Technology Yitu Project Management Kirin Edition 2.3.6 allows a remote attacker to execute arbitrary code via a specially constructed so file/opt/EdrawProj-2/plugins/imageformat.
https://gist.github.com/zty-1995/a7948be24b3411759a6afa3cc616dc12