e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-36981 | e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service. |
Fixes
Solution
Update version to 24.50SP1 or later.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-7329-d8e4c-1.html |
|
History
Wed, 02 Oct 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-10-02T17:39:51.077Z
Reserved: 2023-05-15T02:46:49.300Z
Link: CVE-2023-32756
Updated: 2024-08-02T15:25:37.005Z
Status : Modified
Published: 2023-08-25T08:15:07.747
Modified: 2024-11-21T08:03:59.077
Link: CVE-2023-32756
No data.
OpenCVE Enrichment
No data.
EUVD