ZipSlip Vulnerability in Weintek EasyBuilder Pro
CVE-2023-0104
9.3CRITICAL
What is CVE-2023-0104?
Weintek EasyBuilder Pro is susceptible to a ZipSlip attack due to its handling of malicious project files. When an attacker crafts a compromised project file that exploits this vulnerability, they can execute commands to manipulate the file system, potentially compromising the user's machine and exposing sensitive data. This underscores the importance of securing software against file extraction vulnerabilities to mitigate risks associated with unauthorized access and control.
Affected Version(s)
EasyBuilder Pro cMT 0 <= 6.07.01
EasyBuilder Pro cMT 0 <= 6.07.02.479
EasyBuilder Pro cMT 0 <= 6.08.01.349
References
EPSS Score
21% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Hank Chen and Mars Cheng of PSIRT and Threat Research of TXOne Networks reported this vulnerability to CISA. Patrick Kuo of TXOne Networks also contributed to this research.
