Home
HIGH: 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NMEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
Any version
affected
Description
WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
Problem types
CWE-23 Relative Path Traversal
Product status
Any version
References
www.twcert.org.tw/tw/cp-132-10538-6a26d-1.html
www.twcert.org.tw/en/cp-139-10539-21f45-2.html