CVE-2024-37728 Information

Description

Arbitrary File Read vulnerability in Xi’an Daxi Information Technology Co. Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the \Pic/Indexes\ interface

Reference

https://ti.qianxin.com/vulnerability/notice-list?value=officeweb365 https://www.cnnvd.org.cn/home/warn https://github.com/wy876/POC/blob/main/OfficeWeb365/OfficeWeb365_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E.md https://github.com/xuetang1125/OfficeWeb365/blob/main/OfficeWeb365_%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%20.md

Share on: