CVE-2023-32757: e-Excellence U-Office Force - Arbitrary File Upload
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32757?
CVE-2023-32757 has a severity rating of High due to the potential for arbitrary file uploads by unauthenticated attackers.
How do I fix CVE-2023-32757?
To fix CVE-2023-32757, update the U-Office Force software to the latest version that includes a patch for this vulnerability.
Who is affected by CVE-2023-32757?
CVE-2023-32757 affects users of Edetw U-Office Force version 20.0.7668d.
What can an attacker do with CVE-2023-32757?
An attacker can exploit CVE-2023-32757 to upload arbitrary files, potentially allowing for remote code execution or service disruption.
Is authentication required to exploit CVE-2023-32757?
No, CVE-2023-32757 can be exploited by unauthenticated attackers without any login credentials.