CVE-2024-3227: Panwei eoffice OA Backend save_image.php path traversal
A vulnerability was found in Panwei eoffice OA up to 9.5. It has been declared as critical. This vulnerability affects unknown code of the file /general/system/interface/themeset/saveimage.php of the component Backend. The manipulation of the argument imagetype leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259072.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3227?
CVE-2024-3227 has been declared as critical.
How do I fix CVE-2024-3227?
To fix CVE-2024-3227, update Panwei eoffice OA to a version beyond 9.5.
What component is affected by CVE-2024-3227?
CVE-2024-3227 affects the Backend component of the Panwei eoffice OA software.
Which file is vulnerable in CVE-2024-3227?
The vulnerable file in CVE-2024-3227 is /general/system/interface/theme_set/save_image.php.
What can be exploited in CVE-2024-3227?
CVE-2024-3227 can be exploited through manipulation of the argument image_type.