8.8
CVE-2025-2396
- EPSS 0.65%
- Veröffentlicht 17.03.2025 06:15:26
- Zuletzt bearbeitet 18.11.2025 17:45:59
- Quelle twcert@cert.org.tw
- CVE-Watchlists
- Unerledigt
The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Edetw ≫ U-office Force Version < 28.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.65% | 0.702 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| twcert@cert.org.tw | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.