RULE(RULE ID:337946)

Rule General Information
Release Date: 2024-04-23
Rule Name: Ezoffice text2Html.controller Arbitrary File Read Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Ezoffice is an OA collaborative office software product that has been mainly focused on the mid to high end market for many years. It has a unified basic management platform, achieving unified management of user data, unified allocation of permissions, and unified identity authentication. Unified planning of portal website groups and collaborative office platforms, closely integrating external network information maintenance, customer service, interactive communication, and daily work, effectively improving work efficiency. There is an arbitrary file reading vulnerability at the text2Htm interface of the Wanhu ezOFFICE collaborative management platform, which allows unauthorized attackers to read sensitive files.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.