VYPR

Force

by U Office

CVEs (2)

  • CVE-2022-39022MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.01

    U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.

  • CVE-2022-39025MedOct 31, 2022
    risk 0.40cvss 6.1epss 0.00

    U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.