Tsinghua Unigroup Electronic Archives System Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in Tsinghua Unigroup Electronic Archives System version 3.2.210802(62532). This vulnerability allows remote attackers to manipulate the 'path' argument in the '/System/Cms/downLoad' file, leading to unauthorized access to files on the server. Exploitation of this vulnerability could expose sensitive information such as configuration files or credentials.

Impact

Exploitation of this vulnerability allows for arbitrary file reading on the server, which could lead to exposure of sensitive information.

Reproduction

To reproduce this vulnerability, send a request to the '/System/Cms/downLoad' endpoint with a crafted 'path' parameter that traverses outside of the intended directory. This will allow access to arbitrary files on the server.

Added: Mar 8, 2026, 8:18 AM
Updated: Mar 8, 2026, 8:18 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
3.8
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.