CVE-2022-39022: e-Excellence Inc. U-Office Force - Path Traversal
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39022?
CVE-2022-39022 has been assigned a high severity rating due to its potential to enable unauthorized access to sensitive system files.
How does CVE-2022-39022 affect U-Office Force?
CVE-2022-39022 allows a remote attacker with general user privileges to exploit a path traversal vulnerability to download arbitrary files from the system.
How do I fix CVE-2022-39022?
To mitigate CVE-2022-39022, it is recommended to update U-Office Force to the latest version beyond 20.50.7821d that addresses this path traversal vulnerability.
Who is at risk from CVE-2022-39022?
Organizations using affected versions of U-Office Force are at risk if they have users with general privileges who can exploit this vulnerability.
What can attackers do with CVE-2022-39022?
Attackers exploiting CVE-2022-39022 can download arbitrary files from the system, which may include sensitive data or configuration files.