CVE Published: 25/08/2023 |
CVE Updated: 02/10/2024 |
CVE Year: 2023 Source: twcert |
Vendor: e-Excellence |
Product: U-Office Force Status : PUBLISHED
CVE-2023-32757 Description
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Metrics
CVSS Version: 3.1 |
Base Score: 9.8 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H