Arbitrary File Upload Vulnerability in Official Document Management System by 2100 Technology
CVE-2026-74845
8.7HIGH
What is CVE-2026-74845?
The Official Document Management System developed by 2100 Technology is vulnerable to an arbitrary file upload flaw. This security issue allows authenticated remote attackers to maliciously upload files, potentially executing web shell backdoors on the server. Once exploited, this vulnerability facilitates arbitrary code execution, posing severe risks to the security of sensitive data and overall system integrity. It is crucial for users to address this vulnerability by applying security patches and implementing robust access controls.
Affected Version(s)
Official Document Management System 0 < 5.0.105
