Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NHIGH: 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
7.5.1 (custom)
affected
Description
The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
Problem types
CWE-23 Relative Path Traversal
Product status
7.5.1 (custom)
References
www.twcert.org.tw/tw/cp-132-10364-6ac24-1.html
www.twcert.org.tw/en/cp-139-10365-bf667-2.html