Information Disclosure Vulnerability in Tsinghua Unigroup Electronic Archives System
CVE-2025-0226
Key Information:
- Vendor
- Tsinghua Unigroup
- Status
- Electronic Archives System
- Vendor
- CVE Published:
- 5 January 2025
Badges
Summary
A significant vulnerability exists within the Tsinghua Unigroup Electronic Archives System that allows unauthorized remote access to sensitive information. The flaw resides in the file download functionality located at /collect/PortV4/downLoad.html, where the manipulation of the 'path' argument can lead to unintended information exposure. This exploit has been publicly disclosed, raising concerns about the risk of exploitation in vulnerable systems.
Affected Version(s)
Electronic Archives System 3.2.210802(62532)
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved