Description
The eHRD CTMS developed by Sunnet has an Arbitrary File Reading vulnerability, allowing remote attackers with administrator privileges to exploit Relative Path Traversal to download arbitrary system files.
Problem types
CWE-23 Relative Path Traversal
Product status
Any version
References
www.twcert.org.tw/tw/cp-132-10356-ea431-1.html
www.twcert.org.tw/en/cp-139-10357-7de41-2.html