VYPR
Vendor

U Office

Products
5
CVEs
6
Across products
6
Status
Private

Products

5

Recent CVEs

6
  • CVE-2022-39023MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.01

    U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.

  • CVE-2022-39022MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.01

    U-Office Force Download function has a path traversal vulnerability. A remote attacker with general user privilege can exploit this vulnerability to download arbitrary system file.

  • CVE-2022-39025MedOct 31, 2022
    risk 0.40cvss 6.1epss 0.00

    U-Office Force PrintMessage function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

  • CVE-2022-39024MedOct 31, 2022
    risk 0.40cvss 6.1epss 0.00

    U-Office Force Bulletin function has insufficient filtering for special characters. An unauthenticated remote attacker can exploit this vulnerability to inject JavaScript and perform XSS (Reflected Cross-Site Scripting) attack.

  • CVE-2022-39027MedOct 31, 2022
    risk 0.35cvss 5.4epss 0.00

    U-Office Force Forum function has insufficient filtering for special characters. A remote attacker with general user privilege can inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.

  • CVE-2022-39026MedOct 31, 2022
    risk 0.35cvss 5.4epss 0.00

    U-Office Force UserDefault page has insufficient filtering for special characters in the HTTP header fields. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform XSS (Stored Cross-Site Scripting) attack.