Home
HIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NHIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version
affected
Description
Organization Portal System developed by WellChoose has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Absolute Path Traversal to download arbitrary system files.
Problem types
CWE-36 Absolute Path Traversal
Product status
Any version
References
www.twcert.org.tw/tw/cp-132-10321-3cae5-1.html
www.twcert.org.tw/en/cp-139-10325-70192-2.html