4 results (0.006 seconds)

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

05 Jan 2025 — A vulnerability, which was classified as problematic, was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). This affects an unknown part of the file /Logs/Annals/downLoad.html. The manipulation of the argument path leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. • https://github.com/BxYQ/ld/blob/main/file_read1/poc.py • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

05 Jan 2025 — A vulnerability, which was classified as problematic, has been found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this issue is the function download of the file /collect/PortV4/downLoad.html. The manipulation of the argument path leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. • https://github.com/BxYQ/ld/blob/main/file_read2/poc.py • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

05 Jan 2025 — A vulnerability classified as problematic was found in Tsinghua Unigroup Electronic Archives System 3.2.210802(62532). Affected by this vulnerability is an unknown functionality of the file /setting/ClassFy/exampleDownload.html. The manipulation of the argument name leads to path traversal: '/../filedir'. The attack can be launched remotely. • https://github.com/BxYQ/ld/blob/main/file_read4/poc.py • CWE-23: Relative Path Traversal CWE-25: Path Traversal: '/../filedir' •

CVSS: 5.3EPSS: 0%CPEs: 1EXPL: 1

30 Dec 2024 — A vulnerability was found in Tsinghua Unigroup Electronic Archives Management System 3.2.210802(62532). It has been classified as problematic. Affected is the function download of the file SubjectController.class.php. The manipulation of the argument path leads to information disclosure. It is possible to launch the attack remotely. • https://github.com/BxYQ/zg_fileread • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control •