TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability. Attackers can copy arbitrary files on the user's system and paste them into any path, which poses a potential risk of information leakage or could consume hard drive space by copying files in large volumes.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update to version 0.41.159 or later.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Nov 2025 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TenderDocTransfer developed by Chunghwa Telecom has a Arbitrary File Copy and Paste vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains an Absolute Path Traversal vulnerability. Attackers can copy arbitrary files on the user's system and paste them into any path, which poses a potential risk of information leakage or could consume hard drive space by copying files in large volumes. | |
| Title | Chunghwa Telecom|TenderDocTransfer - Arbitrary File Copy and Paste | |
| Weaknesses | CWE-352 CWE-36 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-11-17T03:30:43.828Z
Reserved: 2025-11-17T02:58:20.490Z
Link: CVE-2025-13283
No data.
Status : Received
Published: 2025-11-17T04:15:54.800
Modified: 2025-11-17T04:15:54.800
Link: CVE-2025-13283
No data.
OpenCVE Enrichment
No data.