U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2022-10-31T06:40:35.568765Z

Updated: 2024-09-17T03:13:35.421Z

Reserved: 2022-08-30T00:00:00

Link: CVE-2022-39023

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-10-31T07:15:10.267

Modified: 2022-10-31T17:46:35.647

Link: CVE-2022-39023

cve-icon Redhat

No data.