Impact
A vulnerability exists in the Download function of Tsinghua Unigroup Electronic Archives System version 3.2.210802(62532). Manipulating the path parameter of the /Search/Subject/downLoad endpoint allows an attacker to access files outside the intended directory, effectively leaking sensitive data. The weakness is a classic path traversal flaw (CWE-22), which can compromise confidentiality and potentially expose system files or configuration data.
Affected Systems
The affected product is Tsinghua Unigroup's Electronic Archives System, specifically the Download feature in version 3.2.210802(62532). No other vendors or versions are known to be impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests exploit probability is low at this moment. It is not listed in the CISA KEV catalog. The vulnerability can be exploited remotely; the attacker need only send a crafted request to the vulnerable endpoint, which is publicly available. Since an exploit has already been released, there is a credible risk of an attacker using the publicly available proof‑of‑concept to gain unauthorized file access.
OpenCVE Enrichment