VYPR

Fengoffice

by Fengoffice

Source repositories

CVEs (6)

  • CVE-2019-9623CriMar 7, 2019
    risk 0.67cvss 9.8epss 0.08

    Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.

  • CVE-2025-5877MedJun 9, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the file /application/models/ApplicationDataObject.class.php of the component Document Upload Handler. The manipulation…

  • CVE-2025-5433MedJun 2, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in Fengoffice Feng Office 3.5.1.5 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php?c=account&a=set_timezone. The manipulation of the argument tz_offset leads to sql injection. The attack may be…

  • CVE-2014-5343Aug 19, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.

  • CVE-2013-5744Oct 28, 2013
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Feng Office 2.3.2-rc and earlier allows remote attackers to inject arbitrary web script or HTML via an arbitrary ref_XXX parameter.

  • CVE-2011-3738Sep 23, 2011
    risk 0.00cvss epss 0.01

    Feng Office 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.