CVE-2022-39023: e-Excellence Inc. U-Office Force - Path Traversal
U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-39023?
CVE-2022-39023 is classified as a high-severity vulnerability due to its potential for an attacker to exploit it for unauthorized file access.
How do I fix CVE-2022-39023?
To mitigate CVE-2022-39023, upgrade U-Office Force to the latest version beyond 20.50.7821d where the vulnerability is addressed.
Who is affected by CVE-2022-39023?
Users of U-Office Force software versions up to and including 20.50.7821d are affected by CVE-2022-39023.
What type of vulnerability is CVE-2022-39023?
CVE-2022-39023 is a path traversal vulnerability that allows unauthorized access to arbitrary files on the system.
Can CVE-2022-39023 be exploited remotely?
Yes, CVE-2022-39023 can be exploited remotely by an attacker with general user privileges.