Tsinghua Unigroup Electronic Archives System Path Traversal Vulnerability
Vulnerability
A path traversal vulnerability has been identified in Tsinghua Unigroup Electronic Archives System version 3.2.210802(62532). This vulnerability allows remote attackers to manipulate the 'path' argument in the '/System/Cms/downLoad' file, leading to unauthorized access to files on the server. Exploitation of this vulnerability could expose sensitive information such as configuration files or credentials.
Impact
Exploitation of this vulnerability allows for arbitrary file reading on the server, which could lead to exposure of sensitive information.
Reproduction
To reproduce this vulnerability, send a request to the '/System/Cms/downLoad' endpoint with a crafted 'path' parameter that traverses outside of the intended directory. This will allow access to arbitrary files on the server.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
