go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

e-Excellence U-Office Force - Improper Authentication

TVN ID TVN-202503002
CVE ID CVE-2025-2395
CVSS 9.8 (Critical)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products U-Office Force before version 28.0
Description The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.
Solution Update to version 28.0 or later
Credit Cyku Hong(DEVCORE)
Public Date 2025-03-17
Top