Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1SCUTF8 allows unauthenticated attackers to browse departments and usernames.
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1SCUTF8 allows attackers to execute arbitrary web scripts or HTML.
dzzoffice 2.02.1SCUTF8 is affected by a Cross Site Scripting (XSS) vulnerability in explorerfile.php. The output of the exit function is printed for the user via exit(jsonencode($return)).