go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

e-Excellence U-Office Force - Arbitrary File Upload

TVN ID TVN-202503003
CVE ID CVE-2025-2396
CVSS 8.8 (High)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products U-Office Force before version 28.0d
Description The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
Solution Update to version 28.0 or later
Credit Cyku Hong(DEVCORE)
Public Date 2025-03-17
Top