Impact
A path traversal flaw exists in the /Using/Subject/downLoad.html component of Tsinghua Unigroup Electronic Archives System version 3.2.210802(62532). Manipulating the path argument allows an attacker to access files outside the intended directory, potentially exposing sensitive data. The vulnerability is a traditional relative path traversal (CWE‑22) and can be used to read arbitrary files on the web server. The information disclosed could compromise confidential documents and potentially expose system configuration or credential information.
Affected Systems
The vulnerability affects the Tsinghua Unigroup Electronic Archives System, specifically the download functionality exposed through /Using/Subject/downLoad.html. The affected version is 3.2.210802(62532). No other editions or patch releases are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, while the EPSS score of less than 1% suggests low exploitation likelihood at the moment. The vulnerability can be triggered remotely over the network by supplying a crafted path parameter, and the exploit code has been made publicly available. The system is not listed in KEV, so no confirmed exploit activity is recorded yet, but the public availability of the exploit raises the threat level for environments that have not yet applied a fix.
OpenCVE Enrichment