Impact
A path traversal vulnerability was found in the /System/Cms/downLoad processing of Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). By manipulating the argument path, a remote attacker can read files outside the intended directory, potentially exposing sensitive configuration or system files. The weakness corresponds to CWE-22 and allows for unauthorized file disclosure or further exploitation if the exposed files contain privileged information.
Affected Systems
The affected product is the Tsinghua Unigroup Electronic Archives System, version 3.2.210802(62532). No other versions or components are listed as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity. The EPSS score is below 1%, suggesting that exploitation is unlikely but not impossible, especially since public exploit code is available. The vulnerability is not listed in CISA’s KEV catalog, but it can be triggered remotely without authentication and may lead to the disclosure of confidential files or facilitate privilege escalation if additional weaknesses exist. Overall, the risk is moderate with a low probability of exploitation under current conditions.
OpenCVE Enrichment