The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6455 | The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. |
Fixes
Solution
Update to version 28.0 or later.
Workaround
No workaround given by the vendor.
References
History
Tue, 18 Nov 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Edetw
Edetw u-office Force |
|
| CPEs | cpe:2.3:a:edetw:u-office_force:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Edetw
Edetw u-office Force |
Mon, 17 Mar 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Mar 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. | |
| Title | e-Excellence U-Office Force - Arbitrary File Upload | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2025-03-17T12:54:14.143Z
Reserved: 2025-03-17T05:39:48.152Z
Link: CVE-2025-2396
Updated: 2025-03-17T12:54:05.234Z
Status : Analyzed
Published: 2025-03-17T06:15:26.113
Modified: 2025-11-18T17:45:59.737
Link: CVE-2025-2396
No data.
OpenCVE Enrichment
No data.
EUVD