Description
The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.
Problem types
CWE-23 Relative Path Traversal
Product status
7.5.1
References
www.twcert.org.tw/tw/cp-132-10364-6ac24-1.html
www.twcert.org.tw/en/cp-139-10365-bf667-2.html