ZipSlip Vulnerability in Weintek EasyBuilder Pro
CVE-2023-0104

9.3CRITICAL

Key Information:

Vendor

Weintek

Vendor
CVE Published:
22 February 2023

What is CVE-2023-0104?

Weintek EasyBuilder Pro is susceptible to a ZipSlip attack due to its handling of malicious project files. When an attacker crafts a compromised project file that exploits this vulnerability, they can execute commands to manipulate the file system, potentially compromising the user's machine and exposing sensitive data. This underscores the importance of securing software against file extraction vulnerabilities to mitigate risks associated with unauthorized access and control.

Affected Version(s)

EasyBuilder Pro cMT 0 <= 6.07.01

EasyBuilder Pro cMT 0 <= 6.07.02.479

EasyBuilder Pro cMT 0 <= 6.08.01.349

References

EPSS Score

21% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hank Chen and Mars Cheng of PSIRT and Threat Research of TXOne Networks reported this vulnerability to CISA. Patrick Kuo of TXOne Networks also contributed to this research.
.