Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2396

Опубликовано: 17 мар. 2025
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:edetw:u-office_force:*:*:*:*:*:*:*:*
Версия до 28.0 (исключая)

EPSS

Процентиль: 70%
0.00647
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
github
11 месяцев назад

The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

EPSS

Процентиль: 70%
0.00647
Низкий

8.8 High

CVSS3

Дефекты

CWE-434