CVE-2023-32757
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthentic
e-Excellence U-Office Force file uploading function does not restrict upload of file with dangerous type. An unauthenticated remote attacker without logging the service can exploit this vulnerability to upload arbitrary files to perform arbitrary command or disrupt service.
CRITICAL · CVSS 9.8
EPSS 0.00608
Schedule remediation
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0